CVE-2021-28191: ASUS BMC's firmware: buffer overflow - Firmware update function
The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-28191.
What is the severity level of CVE-2021-28191?
The severity level of CVE-2021-28191 is medium with a CVSS score of 4.9.
How does the Firmware update function in ASUS BMC's firmware Web management page become vulnerable to buffer overflow?
The vulnerability occurs because the function does not verify the string length entered by users, leading to a buffer overflow.
What can remote attackers potentially do due to the buffer overflow vulnerability in ASUS BMC's firmware Web management page?
Remote attackers can exploit the buffer overflow to obtain privileged permission and abnormally terminate the Web service.
Where can I find more information about the vulnerability CVE-2021-28191 and any related advisories from ASUS?
You can find more information about CVE-2021-28191 and related advisories from ASUS on their official product security advisory page.