Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ASUS BMC's firmware: buffer overflow - SMTP configuration function
Vulnerability Description
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
ASUS BMC Firmware 安全特征问题漏洞
Vulnerability Description
ASUS BMC Firmware是中国华硕(ASUS)公司的一个固件。 ASUS BMC firmware Web management page 存在安全特征问题漏洞,该漏洞源于SMTP configuration function对用户输入的字符串长度不进行验证,导致缓冲区溢出漏洞。远程攻击者可利用该漏洞利用泄漏异常终止Web服务。
CVSS Information
N/A
Vulnerability Type
N/A