logo

Below the EDR: How Unsecured IP-KVM Switches Grant Total System Takeover

ID: 94baec25-9546-5941-8a3b-ffc64c3eb635

STIX ID: report--94baec25-9546-5941-8a3b-ffc64c3eb635

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Eclypsium researchers warn that widely used IP-KVM devices contain multiple vulnerabilities (nine CVEs across four vendors) that can give attackers effective physical-level access to connected systems—bypassing OS-level defenses and enabling BIOS modifications, USB emulation (BadUSB), and persistent firmware compromise; several high-severity flaws remain unpatched, and the report recommends network isolation, removing internet exposure, strong authentication, firmware updates, and active inventory scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.