Vulnerability Description
The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Asmb9-Ikvm Firmware | 1.11.12 |
| Asus | Asmb9-Ikvm | - |
| Asus | Rs720A-E9-Rs24-E Firmware | 1.10.3 |
| Asus | Rs720A-E9-Rs24-E | - |
| Asus | Rs700A-E9-Rs4 Firmware | 1.10.0 |
| Asus | Rs700A-E9-Rs4 | - |
| Asus | Rs700-E9-Rs4 Firmware | 1.09 |
| Asus | Rs700-E9-Rs4 | - |
| Asus | Esc4000 G4X Firmware | 1.11.6 |
| Asus | Esc4000 G4X | - |
| Asus | Rs700-E9-Rs12 Firmware | 1.11.5 |
| Asus | Rs700-E9-Rs12 | - |
| Asus | Rs100-E10-Pi2 Firmware | 1.13.6 |
| Asus | Rs100-E10-Pi2 | - |
| Asus | Rs300-E10-Ps4 Firmware | 1.13.6 |
| Asus | Rs300-E10-Ps4 | - |
| Asus | Rs300-E10-Rs4 Firmware | 1.13.6 |
| Asus | Rs300-E10-Rs4 | - |
| Asus | Rs500A-E9-Ps4 Firmware | 1.14.1 |
| Asus | Rs500A-E9-Ps4 | - |
Related Weaknesses (CWE)
References
- https://www.asus.com/content/ASUS-Product-Security-Advisory/Vendor Advisory
- https://www.asus.com/tw/support/callus/Vendor Advisory
- https://www.twcert.org.tw/tw/cp-132-4560-2f01f-1.htmlThird Party Advisory
- https://www.asus.com/content/ASUS-Product-Security-Advisory/Vendor Advisory
- https://www.asus.com/tw/support/callus/Vendor Advisory
- https://www.twcert.org.tw/tw/cp-132-4560-2f01f-1.htmlThird Party Advisory
FAQ
What is CVE-2021-28190?
CVE-2021-28190 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. A...
How severe is CVE-2021-28190?
CVE-2021-28190 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28190?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Asmb9-Ikvm Firmware, Asus Asmb9-Ikvm, Asus Rs720A-E9-Rs24-E Firmware, Asus Rs720A-E9-Rs24-E, Asus Rs700A-E9-Rs4 Firmware.