CVE-2021-28190: ASUS BMC's firmware: buffer overflow - Generate new certificate function
The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28190?
CVE-2021-28190 has been classified as a critical severity vulnerability due to its potential exploitation for remote code execution.
How do I fix CVE-2021-28190?
To mitigate CVE-2021-28190, update the affected ASUS BMC firmware to the latest version provided by ASUS.
What systems are affected by CVE-2021-28190?
CVE-2021-28190 affects specific versions of ASUS BMC firmware across various hardware models including the Asus Asmb9-ikvm and multiple RS and Esc series firmware versions.
What type of vulnerability is CVE-2021-28190?
CVE-2021-28190 is a buffer overflow vulnerability caused by improper input validation in the certificate generation function.
Can CVE-2021-28190 be exploited remotely?
Yes, CVE-2021-28190 can be exploited remotely by attackers with access to the firmware's web management interface.