CVE-2021-28192: ASUS BMC's firmware: buffer overflow - Remote video storage function
The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28192?
CVE-2021-28192 is classified as a high severity vulnerability due to the potential for remote code execution via buffer overflow.
How do I fix CVE-2021-28192?
The recommended fix for CVE-2021-28192 is to update the ASUS BMC firmware to the latest version provided by ASUS.
Which ASUS firmware versions are affected by CVE-2021-28192?
The affected ASUS firmware versions for CVE-2021-28192 include 1.11.12 for the Asmb9-ikvm Firmware, 1.10.3 for the Rs720a-e9-rs24-e Firmware, and several others listed in security advisories.
What potential impact does CVE-2021-28192 have?
The potential impact of CVE-2021-28192 includes unauthorized access and control over the affected systems via remote exploitation.
Are there any workarounds for CVE-2021-28192?
Temporary mitigation measures for CVE-2021-28192 may include restricting access to the management interface until the firmware is updated.