logo

Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw

ID: c94808a3-aca7-513a-913c-b35535bce96f

STIX ID: report--c94808a3-aca7-513a-913c-b35535bce96f

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-04-15

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Binarly disclosed an out‑of‑bounds read vulnerability in older Lighttpd versions embedded in BMC firmware (notably Intel M70KLP series and Lenovo BMC builds). Although the bug was silently fixed upstream in Lighttpd 1.4.51 (August 2018), the absence of a CVE/advisory and vendor EoL decisions left affected devices unpatched, allowing potential memory disclosure that could aid ASLR bypass and long-term supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.