cbcvebase.
CVE-2021-28206
published 2021-04-06

CVE-2021-28206: The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the…

medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

Affected

88 ranges· showing 25
VendorProductVersion rangeFixed in
asusasmb9-ikvm_firmware
asusbmc_firmware_for_asmb9-ikvm
asusbmc_firmware_for_e700_g4
asusbmc_firmware_for_esc4000_dhd_g4
asusbmc_firmware_for_esc4000_g4
asusbmc_firmware_for_esc4000_g4x
asusbmc_firmware_for_esc8000_g4
asusbmc_firmware_for_esc8000_g4_10g
asusbmc_firmware_for_knpa-u16
asusbmc_firmware_for_pro_e800_g4
asusbmc_firmware_for_rs100-e10-pi2
asusbmc_firmware_for_rs300-e10-ps4
asusbmc_firmware_for_rs300-e10-rs4
asusbmc_firmware_for_rs500-e9-ps4
asusbmc_firmware_for_rs500-e9-rs4
asusbmc_firmware_for_rs500-e9-rs4-u
asusbmc_firmware_for_rs500a-e10-ps4
asusbmc_firmware_for_rs500a-e10-rs4
asusbmc_firmware_for_rs500a-e9-ps4
asusbmc_firmware_for_rs500a-e9-rs4
asusbmc_firmware_for_rs500a-e9_rs4
asusbmc_firmware_for_rs520-e9-rs12-e
asusbmc_firmware_for_rs520-e9-rs8
asusbmc_firmware_for_rs700-e9-rs12
asusbmc_firmware_for_rs700-e9-rs4