ASUS Vulnerabilities and Affected Products
Vulnerabilities associated with HG100 firmware.
Products
Clear product- BMC firmware for ASMB8-iKVM18 vulnerabilities
- BMC firmware for Z10PE-D16 WS18 vulnerabilities
- BMC firmware for Z10PR-D1618 vulnerabilities
- BMC firmware for ASMB9-iKVM17 vulnerabilities
- BMC firmware for E700 G417 vulnerabilities
- BMC firmware for ESC4000 DHD G417 vulnerabilities
- BMC firmware for ESC4000 G417 vulnerabilities
- BMC firmware for ESC4000 G4X17 vulnerabilities
- BMC firmware for ESC8000 G417 vulnerabilities
- BMC firmware for ESC8000 G4/10G17 vulnerabilities
- BMC firmware for KNPA-U1617 vulnerabilities
- BMC firmware for Pro E800 G417 vulnerabilities
- BMC firmware for RS100-E10-PI217 vulnerabilities
- BMC firmware for RS300-E10-PS417 vulnerabilities
- BMC firmware for RS300-E10-RS417 vulnerabilities
- BMC firmware for RS500-E9-PS417 vulnerabilities
- BMC firmware for RS500-E9-RS417 vulnerabilities
- BMC firmware for RS500-E9-RS4-U17 vulnerabilities
- BMC firmware for RS500A-E10-PS417 vulnerabilities
- BMC firmware for RS500A-E10-RS417 vulnerabilities
- BMC firmware for RS500A-E9 RS417 vulnerabilities
- BMC firmware for RS500A-E9-PS417 vulnerabilities
- BMC firmware for RS500A-E9-RS417 vulnerabilities
- BMC firmware for RS520-E9-RS12-E17 vulnerabilities
- BMC firmware for RS520-E9-RS817 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-11060HIGH | HG100 contains an Uncontrolled Resource Consumption vulnerabilityThe web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score 7.4 (Availability impacts). CVSS vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). | CVSS7.5v3.1 | EPSS2.96% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-11061CRITICAL | HG100 has a broken access control vulnerability in its Web API ServerA broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). CWE-306Aug 29, 2019 | CVSS10.0v3.0 | EPSS3.95% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |