The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
2021-04-06T05:15:15.067
2024-11-21T05:59:16.443
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | asus | z10pr-d16_firmware | 1.14.51 | Yes |
Hardware | asus | z10pr-d16 | - | No |
Operating System | asus | asmb8-ikvm_firmware | 1.14.51 | Yes |
Hardware | asus | asmb8-ikvm | - | No |
Operating System | asus | z10pe-d16_ws_firmware | 1.14.2 | Yes |
Hardware | asus | z10pe-d16_ws | - | No |