Learn about CVE-2021-28194, a buffer overflow vulnerability in ASUS BMC's firmware, allowing remote attackers to disrupt the Web service. Find mitigation steps and firmware update recommendations.
A buffer overflow vulnerability in ASUS BMC's firmware allows remote attackers to terminate the Web service by exploiting a specific function in the Web management page.
Understanding CVE-2021-28194
This CVE details a buffer overflow vulnerability in ASUS BMC's firmware, affecting multiple versions.
What is CVE-2021-28194?
The vulnerability stems from the firmware's lack of string length verification, allowing remote attackers to trigger a buffer overflow. This could lead to the abnormal termination of the Web service.
The Impact of CVE-2021-28194
With a CVSS base score of 4.9, this vulnerability has a medium severity rating. It requires high privileges and affects the availability of the system.
Technical Details of CVE-2021-28194
The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) lacks string length verification, leading to a buffer overflow.
Vulnerability Description
The vulnerable function in the firmware enables remote attackers to trigger a buffer overflow, impacting the Web service.
Affected Systems and Versions
Multiple ASUS products running firmware versions like 1.09, 1.10.0, 1.11.5, and more are affected by this vulnerability.
Exploitation Mechanism
Remote attackers can exploit this vulnerability by manipulating the string length input to trigger a buffer overflow and disrupt the Web service.
Mitigation and Prevention
To mitigate the CVE-2021-28194 vulnerability, users are advised to update their BMC firmware to the following versions:
Immediate Steps to Take
Immediately update affected BMC firmware to the patched versions to secure systems against potential exploitation.
Long-Term Security Practices
Regularly check for firmware updates and security advisories from ASUS to stay protected against vulnerabilities.
Patching and Updates
Stay informed about firmware updates and security patches released by ASUS to address known vulnerabilities.