CVE-2021-28201: ASUS BMC's firmware: buffer overflow - Service configuration-1 function
The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28201?
CVE-2021-28201 is rated as critical due to the potential for remote code execution through buffer overflow exploitation.
How do I fix CVE-2021-28201?
To fix CVE-2021-28201, update the affected ASUS BMC firmware to the latest version provided by ASUS.
Which ASUS firmware versions are affected by CVE-2021-28201?
CVE-2021-28201 affects specific firmware versions including ASUS ASMB9-IKVM firmware 1.11.12, RS720A-E9-RS24-E firmware 1.10.3, and several others listed in the advisory.
Can CVE-2021-28201 be exploited remotely?
Yes, CVE-2021-28201 can be exploited remotely by attackers with the ability to send specially crafted input to the web management interface.
What impact does CVE-2021-28201 have on systems?
The impact of CVE-2021-28201 includes unauthorized access, system crashes, or potential execution of arbitrary code leading to compromised systems.