Описание
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:asus:z10pr-d16_firmware:1.14.51:*:*:*:*:*:*:*
cpe:2.3:h:asus:z10pr-d16:-:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:o:asus:asmb8-ikvm_firmware:1.14.51:*:*:*:*:*:*:*
cpe:2.3:h:asus:asmb8-ikvm:-:*:*:*:*:*:*:*
Конфигурация 3
Одновременно
cpe:2.3:o:asus:z10pe-d16_ws_firmware:1.14.2:*:*:*:*:*:*:*
cpe:2.3:h:asus:z10pe-d16_ws:-:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00501
Низкий
4.9 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-22
CWE-22
Связанные уязвимости
github
больше 3 лет назад
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.
EPSS
Процентиль: 65%
0.00501
Низкий
4.9 Medium
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-22
CWE-22