CVE-2021-28189: ASUS BMC's firmware: buffer overflow - SMTP configuration function
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-28189.
What is the severity of CVE-2021-28189?
CVE-2021-28189 has a severity rating of 4.9 (medium).
What is the affected software for CVE-2021-28189?
The affected software for CVE-2021-28189 includes Asus Z10pr-d16 Firmware (version 1.14.51) and Asus Asmb8-ikvm Firmware (version 1.14.51).
How does CVE-2021-28189 exploit the vulnerability?
CVE-2021-28189 exploits a Buffer overflow vulnerability in the SMTP configuration function of ASUS BMC's firmware Web management page.
Are there any patches or fixes available for CVE-2021-28189?
To fix CVE-2021-28189, it is recommended to update the affected firmware to a version that addresses the vulnerability.