ASUS Vulnerabilities and Affected Products
Vulnerabilities associated with BMC firmware for Z10PE-D16 WS.
Products
Clear product- BMC firmware for ASMB8-iKVM18 vulnerabilities
- BMC firmware for Z10PE-D16 WS18 vulnerabilities
- BMC firmware for Z10PR-D1618 vulnerabilities
- BMC firmware for ASMB9-iKVM17 vulnerabilities
- BMC firmware for E700 G417 vulnerabilities
- BMC firmware for ESC4000 DHD G417 vulnerabilities
- BMC firmware for ESC4000 G417 vulnerabilities
- BMC firmware for ESC4000 G4X17 vulnerabilities
- BMC firmware for ESC8000 G417 vulnerabilities
- BMC firmware for ESC8000 G4/10G17 vulnerabilities
- BMC firmware for KNPA-U1617 vulnerabilities
- BMC firmware for Pro E800 G417 vulnerabilities
- BMC firmware for RS100-E10-PI217 vulnerabilities
- BMC firmware for RS300-E10-PS417 vulnerabilities
- BMC firmware for RS300-E10-RS417 vulnerabilities
- BMC firmware for RS500-E9-PS417 vulnerabilities
- BMC firmware for RS500-E9-RS417 vulnerabilities
- BMC firmware for RS500-E9-RS4-U17 vulnerabilities
- BMC firmware for RS500A-E10-PS417 vulnerabilities
- BMC firmware for RS500A-E10-RS417 vulnerabilities
- BMC firmware for RS500A-E9 RS417 vulnerabilities
- BMC firmware for RS500A-E9-PS417 vulnerabilities
- BMC firmware for RS500A-E9-RS417 vulnerabilities
- BMC firmware for RS520-E9-RS12-E17 vulnerabilities
- BMC firmware for RS520-E9-RS817 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-28205MEDIUM | ASUS BMC's firmware: path traversal - Delete SOL video file functionThe specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. CWE-22Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28204HIGH | ASUS BMC's firmware: command injection - Modify user’s information functionThe specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. CWE-78Apr 6, 2021 | CVSS7.2v3.1 | EPSS2.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28203HIGH | ASUS BMC's firmware: command injection - Web Set Media Image functionThe Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. CWE-78Apr 6, 2021 | CVSS7.2v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28189MEDIUM | ASUS BMC's firmware: buffer overflow - SMTP configuration functionThe SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28188MEDIUM | ASUS BMC's firmware: buffer overflow - Modify user’s information functionThe specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28187MEDIUM | ASUS BMC's firmware: buffer overflow - Generate new SSL certificateThe specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28186MEDIUM | ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisitionThe specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28185MEDIUM | ASUS BMC's firmware: buffer overflow - ActiveX configuration-1 acquisitionThe specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28184MEDIUM | ASUS BMC's firmware: buffer overflow - Active Directory configuration functionThe Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28183MEDIUM | ASUS BMC's firmware: buffer overflow - Web License configuration settingThe specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28182MEDIUM | ASUS BMC's firmware: buffer overflow - Web Service configuration functionThe Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28181MEDIUM | ASUS BMC's firmware: buffer overflow - Remote video configuration settingThe specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28180MEDIUM | ASUS BMC's firmware: buffer overflow - Audit log configuration settingThe specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28179MEDIUM | ASUS BMC's firmware: buffer overflow - Media support configuration settingThe specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28178MEDIUM | ASUS BMC's firmware: buffer overflow - UEFI configuration functionThe UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28177MEDIUM | ASUS BMC's firmware: buffer overflow - LDAP configuration functionThe LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28176MEDIUM | ASUS BMC's firmware: buffer overflow - DNS configuration functionThe DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28175MEDIUM | ASUS BMC's firmware: buffer overflow - Radius configuration functionThe Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |