CVE-2021-28198: ASUS BMC's firmware: buffer overflow - Firmware protocol configuration
The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28198?
CVE-2021-28198 is classified as a buffer overflow vulnerability, which can lead to remote code execution and privilege escalation if exploited.
How do I fix CVE-2021-28198?
To fix CVE-2021-28198, update the affected ASUS firmware to the latest version provided by ASUS.
What products are affected by CVE-2021-28198?
CVE-2021-28198 affects multiple ASUS firmware versions including those for the ASMB9-IKVM, RS720A-E9-RS24-E, and several others as detailed in the advisory.
Can CVE-2021-28198 be exploited remotely?
Yes, CVE-2021-28198 can be exploited remotely without user interaction if the attacker has access to the network.
What are the potential consequences of exploiting CVE-2021-28198?
Exploiting CVE-2021-28198 can lead to unauthorized access, data leakage, or denial of service for the affected systems.