Intel and Lenovo servers impacted by 6-year-old BMC flaw
ID: ec5b5921-6e30-56e3-9c29-46f1a279fd65
STIX ID: report--ec5b5921-6e30-56e3-9c29-46f1a279fd65
Feed Name: Bleeping Computer
Threat Score
Binarly researchers discovered a remotely exploitable heap out-of-bounds read in Lighttpd used in BMC firmware (pre-1.4.51) that can leak process memory and facilitate ASLR bypass; an upstream fix from 2018 was silently patched without a CVE and was not integrated by some vendors (notably AMI MegaRAC), causing thousands of Intel, Lenovo, and other vendor devices — many now EOL — to remain vulnerable and publicly exposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
