logo

Intel and Lenovo servers impacted by 6-year-old BMC flaw

ID: ec5b5921-6e30-56e3-9c29-46f1a279fd65

STIX ID: report--ec5b5921-6e30-56e3-9c29-46f1a279fd65

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Binarly researchers discovered a remotely exploitable heap out-of-bounds read in Lighttpd used in BMC firmware (pre-1.4.51) that can leak process memory and facilitate ASLR bypass; an upstream fix from 2018 was silently patched without a CVE and was not integrated by some vendors (notably AMI MegaRAC), causing thousands of Intel, Lenovo, and other vendor devices — many now EOL — to remain vulnerable and publicly exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.