Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BMC firmware for Z10PR-D16 — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in BMC firmware for Z10PR-D16, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities for the Baseboard Management Controller firmware associated with the Supermicro Z10PR-D16 motherboard, categorized under various Common Weakness Enumeration tags such as buffer overflows, privilege escalation flaws, and cross-site scripting risks. The content aggregates publicly disclosed security issues and vendor advisories spanning from the initial release of the firmware through present-day updates, ensuring that administrators have access to a comprehensive timeline of known defects. By reviewing this aggregation, users can effectively track Supermicro’s official security bulletins and patch releases, gain a deeper understanding of how specific weakness classes impact out-of-band management interfaces, and examine the historical evolution of vulnerabilities within this particular hardware platform. This resource is designed to assist system administrators, security engineers, and compliance officers in assessing the security posture of their server infrastructure without needing to scour multiple disparate sources. The data presented here supports informed decision-making regarding firmware updates, mitigation strategies, and risk acceptance for the Z10PR-D16 series. Maintaining awareness of these issues is critical for protecting the underlying server systems from remote exploitation or unauthorized control through the BMC interface. Users are encouraged to cross-reference this information with the latest official documentation from Supermicro to ensure that all identified weaknesses have been adequately addressed in the currently deployed firmware versions. This approach helps minimize the attack surface and ensures that critical management functions remain secure against emerging threats.

Vendor: ASUS

CVE IDTitleCVSSSeverityPublished
CVE-2021-28205 ASUS BMC's firmware: path traversal - Delete SOL video file function CWE-22 4.9 Medium2021-04-06
CVE-2021-28204 ASUS BMC's firmware: command injection - Modify user’s information function CWE-78 7.2 High2021-04-06
CVE-2021-28203 ASUS BMC's firmware: command injection - Web Set Media Image function CWE-78 7.2 High2021-04-06
CVE-2021-28189 ASUS BMC's firmware: buffer overflow - SMTP configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28188 ASUS BMC's firmware: buffer overflow - Modify user’s information function CWE-120 4.9 Medium2021-04-06
CVE-2021-28187 ASUS BMC's firmware: buffer overflow - Generate new SSL certificate CWE-120 4.9 Medium2021-04-06
CVE-2021-28186 ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisition CWE-120 4.9 Medium2021-04-06
CVE-2021-28185 ASUS BMC's firmware: buffer overflow - ActiveX configuration-1 acquisition CWE-120 4.9 Medium2021-04-06
CVE-2021-28184 ASUS BMC's firmware: buffer overflow - Active Directory configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28183 ASUS BMC's firmware: buffer overflow - Web License configuration setting CWE-120 4.9 Medium2021-04-06
CVE-2021-28182 ASUS BMC's firmware: buffer overflow - Web Service configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28181 ASUS BMC's firmware: buffer overflow - Remote video configuration setting CWE-120 4.9 Medium2021-04-06
CVE-2021-28180 ASUS BMC's firmware: buffer overflow - Audit log configuration setting CWE-120 4.9 Medium2021-04-06
CVE-2021-28179 ASUS BMC's firmware: buffer overflow - Media support configuration setting CWE-120 4.9 Medium2021-04-06
CVE-2021-28178 ASUS BMC's firmware: buffer overflow - UEFI configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28177 ASUS BMC's firmware: buffer overflow - LDAP configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28176 ASUS BMC's firmware: buffer overflow - DNS configuration function CWE-120 4.9 Medium2021-04-06
CVE-2021-28175 ASUS BMC's firmware: buffer overflow - Radius configuration function CWE-120 4.9 Medium2021-04-06

All 18 known CVE vulnerabilities affecting BMC firmware for Z10PR-D16 with full Chinese analysis, references, and POCs where available.