CVE-2021-28195: ASUS BMC's firmware: buffer overflow - Radius configuration function
The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28195?
CVE-2021-28195 is classified as a high-severity buffer overflow vulnerability.
How do I fix CVE-2021-28195?
To mitigate CVE-2021-28195, update to the latest firmware version from ASUS that addresses this vulnerability.
Which ASUS firmware versions are affected by CVE-2021-28195?
CVE-2021-28195 affects specific versions of ASUS firmware including 1.11.12, 1.10.3, and several other listed versions for various models.
What types of devices are impacted by CVE-2021-28195?
Devices affected by CVE-2021-28195 include various ASUS server and management firmware solutions like the ASUS RS series and ASMB9-IKVM.
Can CVE-2021-28195 be exploited remotely?
Yes, CVE-2021-28195 can be exploited remotely by attackers with access to the vulnerable configuration interface.