Buggy microcontrollers making up some of the world's most important servers can be easily backdoored
Researchers found more than a dozen new flaws plaguing baseboard management controllers.
Security researchers from runZero disclosed over a dozen new vulnerabilities in baseboard management controllers (BMCs) used in numerous enterprise servers. BMCs, specialized hardware components introduced in the late 1990s, enable administrators to remotely monitor and manage servers' hardware, even when the system is powered off. Found at the Black Hat security conference, the flaws were disclosed by HD Moore of runZero, raising concerns regarding a widespread and under-patched parallel attack surface.
According to Moore, the vulnerabilities found in BMCs from HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell pose a significant risk. During two scans conducted, 86,000 exposed BMCs were discovered in internet-connected devices, with 54% of them carrying at least one of the flaws. Internally, a survey of over 120,000 BMCs revealed that 29% were affected by at least one critical vulnerability.
While many of the flaws can only be exploited with prior authentication, Moore highlighted that smaller pre-authentication flaws also exist and could be abused by well-equipped threat actors. The researchers cautioned that details about the vulnerabilities will remain undisclosed until the affected manufacturers address the issues.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.