CVE-2021-28186: ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisition
The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28186?
The severity of CVE-2021-28186 is medium (4.9).
What software is affected by CVE-2021-28186?
ASUS Z10pr-d16 Firmware version 1.14.51 and ASUS Asmb8-ikvm Firmware version 1.14.51 are affected by CVE-2021-28186.
How does CVE-2021-28186 affect ASUS BMC's firmware Web management page?
CVE-2021-28186 allows remote attackers to cause a buffer overflow vulnerability in the specific function of ASUS BMC's firmware Web management page, potentially leading to abnormal termination.
Is ASUS Z10pr-d16 vulnerable to CVE-2021-28186?
Yes, ASUS Z10pr-d16 with Firmware version 1.14.51 is vulnerable to CVE-2021-28186.
Where can I find more information about CVE-2021-28186?
You can find more information about CVE-2021-28186 in the ASUS Product Security Advisory, ASUS support page, and the Taiwan Computer Emergency Response Team (TW-CERT) advisory.