CVE-2021-28197: ASUS BMC's firmware: buffer overflow - Active Directory configuration function
The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28197?
CVE-2021-28197 is classified as a high-severity vulnerability due to its potential for buffer overflow exploitation.
How do I fix CVE-2021-28197?
To remediate CVE-2021-28197, update the affected ASUS BMC firmware to the latest version provided by ASUS.
What systems are affected by CVE-2021-28197?
CVE-2021-28197 affects multiple ASUS BMC firmware versions, specifically those before the latest release as detailed in the ASUS advisory.
Can CVE-2021-28197 be exploited remotely?
Yes, CVE-2021-28197 can potentially be exploited remotely by an attacker with the correct permissions.
What type of vulnerability is CVE-2021-28197?
CVE-2021-28197 is a buffer overflow vulnerability resulting from inadequate string length validation in the BMC firmware.