cbcvebase.
CVE-2021-28196
published 2021-04-06

CVE-2021-28196: The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users…

medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

Affected

88 ranges· showing 25
VendorProductVersion rangeFixed in
asusasmb9-ikvm_firmware
asusbmc_firmware_for_asmb9-ikvm
asusbmc_firmware_for_e700_g4
asusbmc_firmware_for_esc4000_dhd_g4
asusbmc_firmware_for_esc4000_g4
asusbmc_firmware_for_esc4000_g4x
asusbmc_firmware_for_esc8000_g4
asusbmc_firmware_for_esc8000_g4_10g
asusbmc_firmware_for_knpa-u16
asusbmc_firmware_for_pro_e800_g4
asusbmc_firmware_for_rs100-e10-pi2
asusbmc_firmware_for_rs300-e10-ps4
asusbmc_firmware_for_rs300-e10-rs4
asusbmc_firmware_for_rs500-e9-ps4
asusbmc_firmware_for_rs500-e9-rs4
asusbmc_firmware_for_rs500-e9-rs4-u
asusbmc_firmware_for_rs500a-e10-ps4
asusbmc_firmware_for_rs500a-e10-rs4
asusbmc_firmware_for_rs500a-e9-ps4
asusbmc_firmware_for_rs500a-e9-rs4
asusbmc_firmware_for_rs500a-e9_rs4
asusbmc_firmware_for_rs520-e9-rs12-e
asusbmc_firmware_for_rs520-e9-rs8
asusbmc_firmware_for_rs700-e9-rs12
asusbmc_firmware_for_rs700-e9-rs4