Author Topic: BMC time again: AMI MegaRAC  (Read 1153 times)

0 Members and 1 Guest are viewing this topic.

Offline madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 9173
  • Country: de
  • A qualified hobbyist ;)
BMC time again: AMI MegaRAC
« on: March 19, 2025, 02:23:35 pm »
Media:
- New Critical AMI BMC Vulnerability Enables Remote Server Takeover and Bricking, https://thehackernews.com/2025/03/new-critical-ami-bmc-vulnerability.html
- Critical AMI MegaRAC bug can let attackers hijack, brick servers, https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bug-can-let-attackers-hijack-brick-servers/

Security researchers:
- BMC&C: Redfish Alert 3, https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/

Affected vendors (so far, expected to be more than a dozen):
- Asus
- ASRock Rack
- HPE
- Lenovo
 

Online Halcyon

  • Global Moderator
  • *****
  • Posts: 6801
  • Country: au
Re: BMC time again: AMI MegaRAC
« Reply #1 on: March 21, 2025, 03:30:44 am »
Another perfect reason not to expose management interfaces to the internet, but people keep doing it!

It wasn't that long ago that iLO-1 and iLO-2 interfaces were being popped and replaced with malicious copies of the firmware.

Nothing, other than what you want the public to touch, should ever be on the internet with a public IP or via a port forward, with the exception of your VPN server itself.
 

Offline bitwelder

  • Super Contributor
  • ***
  • Posts: 1048
  • Country: fi
Re: BMC time again: AMI MegaRAC
« Reply #2 on: March 21, 2025, 08:44:52 am »
And besides, for something really critical it might be also worth to consider to disable the BMC entirely (there is likely some dip switch or jumper on the mainbord for that), if the price to pay for the loss of serviceability is acceptable.

 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf