Below the EDR: How Unsecured IP-KVM Switches Grant Total System Takeover
ID: 94baec25-9546-5941-8a3b-ffc64c3eb635
STIX ID: report--94baec25-9546-5941-8a3b-ffc64c3eb635
Feed Name: securityonline.info
Eclypsium researchers warn that widely used IP-KVM devices contain multiple vulnerabilities (nine CVEs across four vendors) that can give attackers effective physical-level access to connected systems—bypassing OS-level defenses and enabling BIOS modifications, USB emulation (BadUSB), and persistent firmware compromise; several high-severity flaws remain unpatched, and the report recommends network isolation, removing internet exposure, strong authentication, firmware updates, and active inventory scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
