CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-28205MEDIUM | ASUS BMC's firmware: path traversal - Delete SOL video file functionThe specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. CWE-22Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28204HIGH | ASUS BMC's firmware: command injection - Modify user’s information functionThe specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. CWE-78Apr 6, 2021 | CVSS7.2v3.1 | EPSS2.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28203HIGH | ASUS BMC's firmware: command injection - Web Set Media Image functionThe Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary. CWE-78Apr 6, 2021 | CVSS7.2v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28189MEDIUM | ASUS BMC's firmware: buffer overflow - SMTP configuration functionThe SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28188MEDIUM | ASUS BMC's firmware: buffer overflow - Modify user’s information functionThe specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28187MEDIUM | ASUS BMC's firmware: buffer overflow - Generate new SSL certificateThe specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28186MEDIUM | ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisitionThe specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28185MEDIUM | ASUS BMC's firmware: buffer overflow - ActiveX configuration-1 acquisitionThe specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28184MEDIUM | ASUS BMC's firmware: buffer overflow - Active Directory configuration functionThe Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28183MEDIUM | ASUS BMC's firmware: buffer overflow - Web License configuration settingThe specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28182MEDIUM | ASUS BMC's firmware: buffer overflow - Web Service configuration functionThe Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28181MEDIUM | ASUS BMC's firmware: buffer overflow - Remote video configuration settingThe specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28180MEDIUM | ASUS BMC's firmware: buffer overflow - Audit log configuration settingThe specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28179MEDIUM | ASUS BMC's firmware: buffer overflow - Media support configuration settingThe specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28178MEDIUM | ASUS BMC's firmware: buffer overflow - UEFI configuration functionThe UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28177MEDIUM | ASUS BMC's firmware: buffer overflow - LDAP configuration functionThe LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28176MEDIUM | ASUS BMC's firmware: buffer overflow - DNS configuration functionThe DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28175MEDIUM | ASUS BMC's firmware: buffer overflow - Radius configuration functionThe Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. CWE-120Apr 6, 2021 | CVSS4.9v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |