CVE-2021-28200: ASUS BMC's firmware: buffer overflow - CD media configuration function
The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28200?
CVE-2021-28200 is classified as a high severity buffer overflow vulnerability that can be exploited remotely.
How do I fix CVE-2021-28200?
To mitigate CVE-2021-28200, users should update their ASUS BMC firmware to the latest version as recommended by ASUS.
Which ASUS products are affected by CVE-2021-28200?
CVE-2021-28200 affects various models including ASUS BMC firmware versions 1.11.12, 1.10.3, 1.10.0, and others listed in the advisory.
Can CVE-2021-28200 be exploited without authentication?
Yes, CVE-2021-28200 can be exploited by remote attackers without prior authentication.
What is the potential impact of CVE-2021-28200?
Exploitation of CVE-2021-28200 may lead to the abnormal termination of the web management service and potential unauthorized access.