CVE-2021-28198: ASUS BMC's firmware: buffer overflow - Firmware protocol configuration

Published Apr 6, 2021
·
Updated

The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

Affected Software

88 affected components
ASUS Asmb9-ikvm Firmware=1.11.12
ASUS Asmb9-ikvm
ASUS Rs720a-e9-rs24-e Firmware=1.10.3
ASUS Rs720a-e9-rs24-e
ASUS Rs700a-e9-rs4 Firmware=1.10.0
ASUS Rs700a-e9-rs4
ASUS Rs700-e9-rs4 Firmware=1.09
ASUS Rs700-e9-rs4
ASUS Esc4000 G4x Firmware=1.11.6
ASUS Esc4000 G4x
ASUS Rs700-e9-rs12 Firmware=1.11.5
ASUS Rs700-e9-rs12
ASUS Rs100-e10-pi2 Firmware=1.13.6
ASUS Rs100-e10-pi2
ASUS Rs300-e10-ps4 Firmware=1.13.6
ASUS Rs300-e10-ps4
ASUS Rs300-e10-rs4 Firmware=1.13.6
ASUS Rs300-e10-rs4
ASUS Rs500a-e9-ps4 Firmware=1.14.1
ASUS Rs500a-e9-ps4
ASUS Rs500a-e9-rs4 Firmware=1.14.1
ASUS Rs500a-e9-rs4
ASUS Rs500a-e9 Rs4 U Firmware=1.14.1
ASUS Rs500a-e9 Rs4 U
ASUS E700 G4 Firmware=1.14.1
ASUS E700 G4
ASUS Ws C422 Pro\/se Firmware=1.14.1
ASUS Ws C422 Pro\/se
ASUS Ws X299 Pro\/se Firmware=1.14.1
ASUS Ws X299 Pro\/se
ASUS Z11pa-u12 Firmware=1.15.1
ASUS Z11pa-u12
ASUS Z11pa-u12\/10g-2s Firmware=1.15.1
ASUS Z11pa-u12\/10g-2s
ASUS Knpa-u16 Firmware=1.13.4
ASUS Knpa-u16
ASUS Esc4000 Dhd G4 Firmware=1.13.7
ASUS Esc4000 Dhd G4
ASUS Esc4000 G4 Firmware=1.15.2
ASUS Esc4000 G4
ASUS Rs720q-e9-rs24-s Firmware=1.15.0
ASUS Rs720q-e9-rs24-s
ASUS Rs720q-e9-rs8 Firmware=1.15.0
ASUS Rs720q-e9-rs8
ASUS Rs720q-e9-rs8-s Firmware=1.15.0
ASUS Rs720q-e9-rs8-s
ASUS Z11pa-d8 Firmware=1.14.1
ASUS Z11pa-d8
ASUS Z11pa-d8c Firmware=1.14.1
ASUS Z11pa-d8c
ASUS Rs720-e9-rs24-u Firmware=1.14.3
ASUS Rs720-e9-rs24-u
ASUS Rs720-e9-rs8-g Firmware=1.15.2
ASUS Rs720-e9-rs8-g
ASUS Rs500-e9-ps4 Firmware=1.15.4
ASUS Rs500-e9-ps4
ASUS Pro E800 G4 Firmware=1.14.2
ASUS Pro E800 G4
ASUS Rs500-e9-rs4 Firmware=1.15.4
ASUS Rs500-e9-rs4
ASUS Rs500-e9-rs4-u Firmware=1.15.4
ASUS Rs500-e9-rs4-u
ASUS Rs520-e9-rs12-e Firmware=1.15.3
ASUS Rs520-e9-rs12-e
ASUS Rs520-e9-rs8 Firmware=1.15.3
ASUS Rs520-e9-rs8
ASUS Esc8000 G4 Firmware=1.15.4
ASUS Esc8000 G4
ASUS Esc8000 G4\/10g Firmware=1.15.4
ASUS Esc8000 G4\/10g
ASUS Rs720-e9-rs12-e Firmware=1.15.2
ASUS Rs720-e9-rs12-e
ASUS Ws C621e Sage Firmware=1.15.1
ASUS Ws C621e Sage
ASUS Rs500a-e10-ps4 Firmware=1.15.2
ASUS Rs500a-e10-ps4
ASUS Rs500a-e10-rs4 Firmware=1.15.2
ASUS Rs500a-e10-rs4
ASUS Rs700a-e9-rs12v2 Firmware=1.15.1
ASUS Rs700a-e9-rs12v2
ASUS Rs700a-e9-rs4v2 Firmware=1.15.1
ASUS Rs700a-e9-rs4v2
ASUS Rs720a-e9-rs12v2 Firmware=1.15.2
ASUS Rs720a-e9-rs12v2
ASUS Rs720a-e9-rs24v2 Firmware=1.15.1
ASUS Rs720a-e9-rs24v2
ASUS Z11pr-d16 Firmware=1.15.3
ASUS Z11pr-d16

Remediation

Information

update BMC's firmwares to the following versions: ESC4000 G4X 1.15.6 RS700-E9-RS12 1.15.4 RS100-E10-PI2 1.15.3 RS300-E10-PS4 1.15.3 RS300-E10-RS4 1.15.3 RS500A-E9-PS4 1.14.2 RS500A-E9-RS4 1.14.2 RS500A-E9 RS4 U 1.14.2 E700 G4 1.14.2 WS C422 PRO/SE 1.14.2 WS X299 PRO/SE 1.14.2 Z11PA-U12 1.15.2 KNPA-U16 1.14.5 ESC4000 DHD G4 1.15.2 ESC4000 G4 1.15.6 RS720Q-E9-RS24-S 1.15.1 RS720Q-E9-RS8 1.15.1 RS720Q-E9-RS8-S 1.15.1 Z11PA-D8 1.15.2 Z11PA-D8C 1.15.2 RS720-E9-RS24-U 1.15.5 RS720-E9-RS8-G 1.15.4 RS500-E9-PS4 1.15.5 Pro E800 G4 1.15.2 RS500-E9-RS4 1.15.5 RS500-E9-RS4-U 1.15.5 RS520-E9-RS12-E 1.15.4 RS520-E9-RS8 1.15.4 ESC8000 G4 1.15.5 ESC8000 G4/10G 1.15.5 RS720-E9-RS12-E 1.15.3 WS C621E SAGE 1.15.3 RS500A-E10-PS4 1.15.3 RS500A-E10-RS4 1.15.3 RS700A-E9-RS12V2 1.15.3 RS700A-E9-RS4V2 1.15.3 RS720A-E9-RS12V2 1.15.3 RS720A-E9-RS24V2 1.15.3 Z11PR-D16 1.15.4

Event History

Apr 6, 2021
CVE Published
via MITRE·05:02 AM
Data Sourced
via MITRE·05:02 AM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-28198?

CVE-2021-28198 is classified as a buffer overflow vulnerability, which can lead to remote code execution and privilege escalation if exploited.

2

How do I fix CVE-2021-28198?

To fix CVE-2021-28198, update the affected ASUS firmware to the latest version provided by ASUS.

3

What products are affected by CVE-2021-28198?

CVE-2021-28198 affects multiple ASUS firmware versions including those for the ASMB9-IKVM, RS720A-E9-RS24-E, and several others as detailed in the advisory.

4

Can CVE-2021-28198 be exploited remotely?

Yes, CVE-2021-28198 can be exploited remotely without user interaction if the attacker has access to the network.

5

What are the potential consequences of exploiting CVE-2021-28198?

Exploiting CVE-2021-28198 can lead to unauthorized access, data leakage, or denial of service for the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203