VYPR
Unrated severityNVD Advisory· Published Oct 24, 2022· Updated May 7, 2025

TLS Certificate Generation Function Improper Input Validation

CVE-2021-44769

Description

An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition which can only be reverted via a factory reset. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper input validation in TLS certificate generation in Lanner IAC-AST2500A BMC firmware allows authenticated remote attackers to cause a permanent DoS requiring factory reset.

Vulnerability

An improper input validation vulnerability exists in the TLS certificate generation function of Lanner IAC-AST2500A BMC firmware version 1.10.0. This issue allows an authenticated remote attacker to trigger a Denial-of-Service (DoS) condition that can only be reverted via a factory reset [1][2].

Exploitation

An attacker with network access and valid authentication credentials can exploit this vulnerability by sending a crafted request to the TLS certificate generation function. The improper input validation causes the BMC to enter an unrecoverable state, requiring physical access to perform a factory reset [2].

Impact

Successful exploitation results in a complete denial of service of the BMC, making it inaccessible to users. The device cannot be recovered without a factory reset, which erases all configuration and data. The CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) [2].

Mitigation

Lanner has released updated firmware versions that fix the issue, available from Lanner technical support. Asset owners should apply the update as soon as possible. No workarounds are documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.