CVE-2021-44769
An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition which can only be reverted via a factory reset.
An authenticated remote attacker would be able to make the BMC inaccessible to users, until a factory reset is performed.
October 21, 2022
The vulnerability affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0
CVE-2021-44769
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
4.9
Updated BMC firmware versions that fix the issue are available from Lanner technical support
Andrea Palanca of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

