VYPR
Unrated severityNVD Advisory· Published Apr 6, 2021· Updated Sep 16, 2024

ASUS BMC's firmware: command injection - Web Set Media Image function

CVE-2021-28203

Description

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Supermicro/Bmcllm-fuzzy
  • ASUS/BMC firmware for ASMB8-iKVMv5
    Range: 1.14.51
  • ASUS/BMC firmware for Z10PE-D16 WSv5
    Range: 1.14.2
  • ASUS/BMC firmware for Z10PR-D16v5
    Range: 1.14.51

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.