Buggy microcontrollers making up some of the world's most important servers can be easily backdoored

https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-2121-80.jpg
  • runZero disclosed 12+ new flaws in BMCs from HPE, Supermicro, Dell, Lenovo, Huawei, and others at Black Hat
  • Scans found 86k internet‑exposed BMCs and 120k internal devices
  • Researchers warn BMCs form a widespread, under‑patched parallel attack surface

Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular enterprise servers.

BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide out-of-band management capabilities such as remote console access, firmware updates, hardware health monitoring, and power control, and have been a pivotal component since their introduction in the late 1990s.

Earlier this week, during the Black Hat security conference in Las Vegas, security expert HD Moore of runZero disclosed finding more than a dozen...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more