vendor:
ASMB8 iKVM
by:
d1g@segfault.net
6.1
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: ASMB8 iKVM
Affected Version From: <= 1.14.51
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2023-26602
CPE: h:asus:asmb8_ikvm_firmware:1.14.51
Platforms Tested: Linux
2023
ASUS ASMB8 iKVM 1.14.51 – Remote Code Execution (RCE)
A vulnerability was found in ASUS ASMB8 iKVM Firmware version 1.14.51 and potentially in other versions. By leveraging SNMP arbitrary extensions, an attacker can execute commands on the system with root privileges and bypass SSH restrictions to introduce a new user.
Mitigation:
Update ASMB8 iKVM firmware to a version higher than 1.14.51. Disable SNMPv2 if not required. Change default credentials and avoid using easily guessable passwords.