CVE-2021-28175: ASUS BMC's firmware: buffer overflow - Radius configuration function
The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-28175?
CVE-2021-28175 is a vulnerability in the Radius configuration function in ASUS BMC’s firmware Web management page that allows remote attackers to cause a buffer overflow and terminate the Web service.
What is the severity of CVE-2021-28175?
CVE-2021-28175 has a severity value of 4.9, which is considered medium.
How does CVE-2021-28175 impact ASUS Z10pr-d16 Firmware?
CVE-2021-28175 affects ASUS Z10pr-d16 Firmware version 1.14.51, allowing remote attackers to exploit a buffer overflow vulnerability.
Is ASUS Z10pr-d16 vulnerable to CVE-2021-28175?
ASUS Z10pr-d16 is vulnerable to CVE-2021-28175 if it is running firmware version 1.14.51.
How can I fix CVE-2021-28175?
To fix CVE-2021-28175, it is recommended to update ASUS BMC firmware to a version that addresses the vulnerability.