CVE-2021-28202: ASUS BMC's firmware: buffer overflow - Service configuration-2 function
The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28202?
CVE-2021-28202 is classified as a buffer overflow vulnerability which may lead to code execution or denial of service if exploited.
How do I fix CVE-2021-28202?
To fix CVE-2021-28202, update the affected ASUS BMC firmware to the latest version provided by ASUS.
Which ASUS products are affected by CVE-2021-28202?
CVE-2021-28202 affects specific versions of ASUS firmware, including the ASMB9-IKVM Firmware version 1.11.12 and several others listed in the advisory.
Can CVE-2021-28202 be exploited remotely?
Yes, CVE-2021-28202 can be exploited remotely by attackers with privileged access to the affected device.
What impact does CVE-2021-28202 have on systems?
Exploiting CVE-2021-28202 can lead to an abnormal termination of the web service or potentially allow remote code execution.