ASUS BMC's firmware: buffer overflow - Generate new SSL certificate
CVE-2021-28187
4.9MEDIUM
Key Information:
- Vendor
Asus
- Vendor
- CVE Published:
- 6 April 2021
What is CVE-2021-28187?
The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Affected Version(s)
BMC firmware for ASMB8-iKVM 1.14.51
BMC firmware for Z10PE-D16 WS 1.14.2
BMC firmware for Z10PR-D16 1.14.51