#megarac — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #megarac, aggregated by home.social.
-
Actively #exploited #vulnerability gives extraordinary control over #server fleets
The vulnerability, carrying a #severity rating of 10 out of a possible 10, resides in the #AMIMegaRAC , a widely used #firmware package that allows large fleets of servers to be remotely accessed and managed even when power is unavailable or the operating system isn't functioning.
#security #ami #megarac -
MegaRAC has a critical flaw allowing hackers to bypass authentication and take full control of servers.
#cybersecurity #authentication #MegaRAC #hacking
https://cnews.link/critical-flaw-affect-server-remote-management-megarac-1/
-
Critical #AMI #MegaRAC bug can let attackers hijack, brick #servers
MegaRAC #BMC provides "lights-out" and "out-of-band" remote system management capabilities that help admins troubleshoot servers as if they were physically in front of the devices. The firmware is used by over a dozen #server vendors that provide equipment to many cloud service and #datacenter providers, including #HPE, #Asus, #ASRock, and others.
https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bug-can-let-attackers-hijack-brick-servers/ -
#Intel and #Lenovo servers impacted by 6-year-old #BMC flaw
During recent scans of Baseboard Management Controllers, Binarly firmware security firm discovered a remotely exploitable heap out-of-bounds read vulnerability through the #Lighttpd web server processing "folded" HTTP request headers.
It was addressed in August 2018, the maintainers of Lighthttpd patched it silently in version 1.4.51 but #AMI #MegaRAC BMC to missed the fix, possibly because no #CVE was assigned.
https://www.bleepingcomputer.com/news/security/intel-and-lenovo-servers-impacted-by-6-year-old-bmc-flaw/