Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw
ID: c94808a3-aca7-513a-913c-b35535bce96f
STIX ID: report--c94808a3-aca7-513a-913c-b35535bce96f
Feed Name: The Hacker News
Threat Score
Binarly disclosed an out‑of‑bounds read vulnerability in older Lighttpd versions embedded in BMC firmware (notably Intel M70KLP series and Lenovo BMC builds). Although the bug was silently fixed upstream in Lighttpd 1.4.51 (August 2018), the absence of a CVE/advisory and vendor EoL decisions left affected devices unpatched, allowing potential memory disclosure that could aid ASLR bypass and long-term supply-chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
