CVE-2021-28193: ASUS BMC's firmware: buffer overflow - SMTP configuration function
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28193?
CVE-2021-28193 is classified as a high severity vulnerability due to its potential for exploitation leading to buffer overflow issues.
How do I fix CVE-2021-28193?
To mitigate CVE-2021-28193, update your ASUS BMC firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2021-28193?
CVE-2021-28193 affects specific ASUS hardware firmware versions including ASMB9-IKVM, RS720A-E9-RS24-E, RS700A-E9-RS4, and others as listed in the advisory.
Can CVE-2021-28193 be exploited remotely?
Yes, CVE-2021-28193 can be exploited remotely by attackers with access to the affected systems.
What are the potential consequences of CVE-2021-28193 exploitation?
Exploitation of CVE-2021-28193 may lead to abnormal termination of web services, resulting in denial of service and possible unauthorized privileges.