CVE-2021-28177: ASUS BMC's firmware: buffer overflow - LDAP configuration function
The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-28177?
CVE-2021-28177 is a vulnerability in ASUS BMC's firmware Web management page that allows remote attackers to exploit a buffer overflow vulnerability.
What is the severity of CVE-2021-28177?
CVE-2021-28177 has a severity rating of 4.9, which is considered medium.
Which software versions are affected by CVE-2021-28177?
ASUS Z10pr-d16 firmware version 1.14.51 and ASUS Asmb8-ikvm firmware version 1.14.51 are affected by CVE-2021-28177.
How can remote attackers exploit CVE-2021-28177?
Remote attackers can exploit CVE-2021-28177 by using the leaked privileged permission to abnormally terminate the Web service.
How can CVE-2021-28177 be fixed?
To fix CVE-2021-28177, it is recommended to update the firmware to a version that addresses the vulnerability. Please refer to the ASUS Product Security Advisory for more information.