CVE-2021-28196: ASUS BMC's firmware: buffer overflow - Generate SSL certificate function
The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28196?
CVE-2021-28196 has a severity rating of high due to its potential to allow remote code execution.
How do I fix CVE-2021-28196?
To fix CVE-2021-28196, update the ASUS BMC firmware to a version that addresses this buffer overflow vulnerability.
Which systems are affected by CVE-2021-28196?
CVE-2021-28196 affects specific versions of ASUS firmware, including ASMB9-IKVM Firmware v1.11.12 and others listed in the vulnerability report.
Can CVE-2021-28196 be exploited remotely?
Yes, CVE-2021-28196 can be exploited remotely by attackers if they can access the affected firmware's web management page.
What are the potential consequences of CVE-2021-28196?
Exploitation of CVE-2021-28196 could lead to unauthorized access and control over affected systems, potentially allowing attackers to execute arbitrary code.