CVE-2021-28199: ASUS BMC's firmware: buffer overflow - Modify user’s information function
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28199?
CVE-2021-28199 is classified as a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2021-28199?
To mitigate CVE-2021-28199, update the affected ASUS BMC firmware to the latest recommended version.
Which ASUS firmware versions are affected by CVE-2021-28199?
CVE-2021-28199 affects specific versions of ASUS BMC firmware, including firmware versions 1.11.12, 1.10.3, and 1.10.0, among others.
What are the risks associated with CVE-2021-28199?
The risks associated with CVE-2021-28199 include potential unauthorized access and remote code execution capabilities for attackers.
Can I detect CVE-2021-28199 on my systems?
Yes, you can detect CVE-2021-28199 by checking if your ASUS BMC firmware includes any of the affected versions.