CVE-2021-28207

CWE-22Path Traversal3 documents3 sources
Severity
4.9MEDIUM
EPSS
0.4%
top 37.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateMay 24

Description

The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages88 packages

🔴Vulnerability Details

2
GHSA
GHSA-98hm-w38p-p29q: The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter2022-05-24
CVEList
ASUS BMC's firmware: path traversal - Get Help file function2021-04-06