CVE-2021-28181: ASUS BMC's firmware: buffer overflow - Remote video configuration setting
The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-28181?
CVE-2021-28181 is a vulnerability found in ASUS BMC's firmware Web management page that allows remote attackers to perform a buffer overflow attack.
How does CVE-2021-28181 impact ASUS BMC's firmware Web management page?
CVE-2021-28181 allows remote attackers to exploit a buffer overflow vulnerability in the specific function of the firmware Web management page.
What is the severity of CVE-2021-28181?
CVE-2021-28181 has a severity rating of 4.9 (medium).
Which versions of ASUS Z10pr-d16 Firmware are affected by CVE-2021-28181?
ASUS Z10pr-d16 Firmware version 1.14.51 is affected by CVE-2021-28181.
How can I fix CVE-2021-28181?
To fix CVE-2021-28181, it is recommended to update ASUS BMC's firmware to a version that addresses the buffer overflow vulnerability.