Логотип exploitDog
bind:CVE-2021-28208
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-28208

Количество 2

Количество 2

nvd логотип

CVE-2021-28208

почти 5 лет назад

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-jc8j-8m78-82j5

больше 3 лет назад

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-28208

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVSS3: 4.9
1%
Низкий
почти 5 лет назад
github логотип
GHSA-jc8j-8m78-82j5

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу