CVE-2021-28194: ASUS BMC's firmware: buffer overflow - Remote image configuration setting
The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28194?
CVE-2021-28194 is categorized as a buffer overflow vulnerability that can lead to remote code execution if exploited.
How do I fix CVE-2021-28194?
To mitigate CVE-2021-28194, update the affected ASUS BMC firmware to the latest version as recommended by ASUS.
Which ASUS firmware versions are affected by CVE-2021-28194?
The vulnerability impacts multiple ASUS firmware versions, including 1.11.12, 1.10.3, 1.10.0, 1.11.6, and 1.13.6.
What are the potential consequences of CVE-2021-28194 exploitation?
Exploitation of CVE-2021-28194 could allow remote attackers to gain unauthorized access and execute arbitrary code on the targeted devices.
Is there any workaround for CVE-2021-28194 prior to applying the patch?
Until a patch is applied, it is advised to restrict network access to affected devices and monitor for unusual activity.