Close Menu
Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Subscribe
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Home»Tech»Server Maintenance: Serious BMC vulnerabilities could lead to supply chain attacks
    Tech

    Server Maintenance: Serious BMC vulnerabilities could lead to supply chain attacks

    Theodore MeeksBy Theodore MeeksDecember 6, 2022No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    Server Maintenance: Serious BMC vulnerabilities could lead to supply chain attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    1. Server Maintenance: Serious BMC vulnerabilities could lead to supply chain attacks

    Attackers can target vulnerabilities in American Megatrend Inc.’s Baseboard Management Controller (BMC) modules. (AMI) and using malicious code to attack servers in cloud data centers, for example.

    Dangerous supply chain

    Administrators can maintain servers remotely using a BMC management solution (keywords: out of range, lights). AMI Remote Maintenance is widespread and used by AMD, Asus, Dell, Nvidia, Qualcomm, and others.

    According to a report by security researchers at Eclypsium, the three vulnerabilities (CVE-2022-40259)criticalCVE-2022-40242highCVE-2022-2827high”) in BMC firmware. As a result, all manufacturers are affected by vulnerabilities. In such a situation, one speaks of an attack on the supply chain.

    Malicious code attacks are possible

    If the attackers succeed in targeting the first vulnerabilities, they will have an admin shell at their disposal. Then they can, among other things, execute malicious code and compromise entire server regions. For this, attackers would just have to send prepared URLs to the Redfish remote management interface, for example. There was a similar case in early 2022, when a rootkit slipped through a hole in HPE’s remote maintenance iLO.

    According to security researchers, it is not yet known if there have already been attacks in the current case. The researchers’ report does not specifically say whether there are already security patches for the vulnerabilities mentioned. Even if there are security patches, it’s difficult to install updates across the board because there are so many parties and products involved. A major problem with supply chain attacks.

    Effectively secure

    In their general safety guidelines, they advise administrators to, among other things, keep all servers up to date and not make BMC publicly accessible. If there is no other way, administrators must secure VPN or SSH access against unauthorized access with strong authentication. Security researchers say that after scanning they only discovered a relatively small number of BMCs that could be directly accessed online.


    (From)

    to the home page

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Theodore Meeks

    Lifelong foodaholic. Professional twitter expert. Organizer. Award-winning internet geek. Coffee advocate.

    Related Posts

    Neodymium Magnet Uses and Safety Tips for 2025

    October 4, 2025

    Halifax Stanfield Airport Pilots Passenger Service Robots in Bid to Boost Traveler Experience

    August 25, 2025

    Battery miracle in test – HP Omnibook X AI: If it takes longer again

    August 29, 2024
    Navigate
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Pages
    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    STAY UPTODATE

    Get the Latest News With Aviationanalysis.net

    OFFICE

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    QUERIES?

    Do you have any queries? Feel free to contact us via our Contact Form

    Visit Our Office

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.