CVE-2021-28182
06.04.2021, 05:15
The Web Service configuration function in ASUS BMCs firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Vendor | Product | Version |
---|---|---|
asus | z10pr-d16_firmware | 1.14.51 |
asus | asmb8-ikvm_firmware | 1.14.51 |
asus | z10pe-d16_ws_firmware | 1.14.2 |
𝑥
= Vulnerable software versions
References