ASUS BMC's firmware: command injection - Modify user’s information function
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in ASUS BMC's web management page allows an attacker with administrator access to inject and execute arbitrary commands through the user modification function by exploiting unfiltered parameters. This could give attackers full control over the system.
Technical detail
CWE-78 command injection vulnerability in ASUS BMC firmware's web management interface affects the user information modification endpoint. An authenticated attacker with administrator privileges can inject OS commands through insufficiently sanitized parameters, leading to arbitrary command execution with BMC-level privileges.
Summary generated and translated by AI from the official description.
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H