CVE-2021-41289

ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BIOS by replacing or filling in the content of the designated Memory DataBuffer, which causing a failure of integrity verification and further resulting in a failure to boot.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:p453uj_bios:311:*:*:*:*:*:*:*
cpe:2.3:h:asus:p453uj:-:*:*:*:*:*:*:*

History

13 Dec 2021, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:asus:p453uj_bios:311:*:*:*:*:*:*:* cpe:2.3:o:asus:p453uj_bios:311:*:*:*:*:*:*:*

18 Nov 2021, 03:59

Type Values Removed Values Added
References (MISC) https://www.twcert.org.tw/tw/cp-132-5284-35790-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-5284-35790-1.html - Third Party Advisory
References (MISC) https://www.asus.com/tw/supportonly/P453UJ/HelpDesk_BIOS/ - (MISC) https://www.asus.com/tw/supportonly/P453UJ/HelpDesk_BIOS/ - Vendor Advisory
CVSS v2 : unknown
v3 : 6.3
v2 : 3.6
v3 : 7.1
CPE cpe:2.3:a:asus:p453uj_bios:311:*:*:*:*:*:*:*
cpe:2.3:h:asus:p453uj:-:*:*:*:*:*:*:*

17 Nov 2021, 12:15

Type Values Removed Values Added
References
  • (MISC) https://www.asus.com/tw/supportonly/P453UJ/HelpDesk_BIOS/ -

15 Nov 2021, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-15 10:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-41289

Mitre link : CVE-2021-41289

CVE.ORG link : CVE-2021-41289


JSON object : View

Products Affected

asus

  • p453uj_bios
  • p453uj
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer