go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ASUS BMC's firmware: command injection - Modify user's information function

TVN ID TVN-202103031
CVE ID CVE-2021-28204
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products BMC's firmwares:
Z10PR-D16 1.14.51
ASMB8-iKVM 1.14.51
Z10PE-D16 WS 1.14.2
Description The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
Solution update BMC's firmwares to the following versions:
Z10PR-D16 1.16.1
ASMB8-iKVM 1.16.1
Z10PE-D16 WS 1.16.1
Credit ASUS
Public Date 2021-04-06
Top