CVE-2021-28191

EUVD-2021-14881
The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
twcertCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
asusasmb9-ikvm_firmware
1.11.12
asusrs720a-e9-rs24-e_firmware
1.10.3
asusrs700a-e9-rs4_firmware
1.10.0
asusrs700-e9-rs4_firmware
1.09
asusesc4000_g4x_firmware
1.11.6
asusrs700-e9-rs12_firmware
1.11.5
asusrs100-e10-pi2_firmware
1.13.6
asusrs300-e10-ps4_firmware
1.13.6
asusrs300-e10-rs4_firmware
1.13.6
asusrs500a-e9-ps4_firmware
1.14.1
asusrs500a-e9-rs4_firmware
1.14.1
asusrs500a-e9_rs4_u_firmware
1.14.1
asuse700_g4_firmware
1.14.1
asusws_c422_pro\/se_firmware
1.14.1
asusws_x299_pro\/se_firmware
1.14.1
asusz11pa-u12_firmware
1.15.1
asusz11pa-u12\/10g-2s_firmware
1.15.1
asusknpa-u16_firmware
1.13.4
asusesc4000_dhd_g4_firmware
1.13.7
asusesc4000_g4_firmware
1.15.2
asusrs720q-e9-rs24-s_firmware
1.15.0
asusrs720q-e9-rs8_firmware
1.15.0
asusrs720q-e9-rs8-s_firmware
1.15.0
asusz11pa-d8_firmware
1.14.1
asusz11pa-d8c_firmware
1.14.1
asusrs720-e9-rs24-u_firmware
1.14.3
asusrs720-e9-rs8-g_firmware
1.15.2
asusrs500-e9-ps4_firmware
1.15.4
asuspro_e800_g4_firmware
1.14.2
asusrs500-e9-rs4_firmware
1.15.4
asusrs500-e9-rs4-u_firmware
1.15.4
asusrs520-e9-rs12-e_firmware
1.15.3
asusrs520-e9-rs8_firmware
1.15.3
asusesc8000_g4_firmware
1.15.4
asusesc8000_g4\/10g_firmware
1.15.4
asusrs720-e9-rs12-e_firmware
1.15.2
asusws_c621e_sage_firmware
1.15.1
asusrs500a-e10-ps4_firmware
1.15.2
asusrs500a-e10-rs4_firmware
1.15.2
asusrs700a-e9-rs12v2_firmware
1.15.1
asusrs700a-e9-rs4v2_firmware
1.15.1
asusrs720a-e9-rs12v2_firmware
1.15.2
asusrs720a-e9-rs24v2_firmware
1.15.1
asusz11pr-d16_firmware
1.15.3
𝑥
= Vulnerable software versions