• Автор темы News
  • Дата начала
  • " /> News - Hackable Intel and Lenovo hardware that went undetected for 5 years won’t ever be fixed | SoftoolStore.de - Софт, Avid Media Composer, Книги. | бесплатные прокси (HTTP, Socks 4, Socks 5)

    News Hackable Intel and Lenovo hardware that went undetected for 5 years won’t ever be fixed

    News

    Команда форума
    Редактор
    Сообщения
    13 823
    Баллы
    358
    Offline
    #1

    Enlarge (credit: Intel)


    Hardware sold for years by the likes of Intel and Lenovo contains a remotely exploitable vulnerability that will never be fixed. The cause: a supply chain snafu involving an open source software package and hardware from multiple manufacturers that directly or indirectly incorporated it into their products.

    Researchers from security firm Binarly have confirmed that the lapse has resulted in Intel, Lenovo, and Supermicro shipping server hardware that contains a vulnerability that can be exploited to reveal security-critical information. The researchers, however, went on to warn that any hardware that incorporates certain generations of baseboard management controllers made by Duluth, Georgia-based AMI or Taiwan-based AETN are also affected.

    Chain of fools


    BMCs are tiny computers soldered into the motherboard of servers that allow cloud centers, and sometimes their customers, to streamline the remote management of vast fleets of servers. They enable administrators to remotely reinstall OSes, install and uninstall apps, and control just about every other aspect of the system—even when it's turned off. BMCs provide what’s known in the industry as “lights-out” system management. AMI and AETN are two of several makers of BMCs.


    Read 11 remaining paragraphs | Comments
     
    Вверх Снизу