← voltar
CVE-2021-28180mediumCWE-120

ASUS BMC's firmware: buffer overflow - Audit log configuration setting

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 4.9epss 1.8%
probabilidade de exploração
1.8%top 23% das CVEs
exploração observada
nãonenhuma fonte reporta
The specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H