CVE-2021-28208

CWE-22Path Traversal3 documents3 sources
Severity
4.9MEDIUM
EPSS
0.4%
top 37.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateMay 24

Description

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages88 packages

🔴Vulnerability Details

2
GHSA
GHSA-jc8j-8m78-82j5: The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter2022-05-24
CVEList
ASUS BMC's firmware: path traversal - Get video file function2021-04-06
CVE-2021-28208 (MEDIUM CVSS 4.9) | The specific function in ASUS BMC’s | cvebase.io