CVE-2021-28205

CWE-22Path Traversal3 documents3 sources
Severity
4.9MEDIUM
EPSS
0.4%
top 37.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateMay 24

Description

The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-pjx3-2523-w68g: The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter2022-05-24
CVEList
ASUS BMC's firmware: path traversal - Delete SOL video file function2021-04-06