Security News > 2023 > July > Critical AMI MegaRAC bugs can let hackers brick vulnerable servers

Critical AMI MegaRAC bugs can let hackers brick vulnerable servers
2023-07-20 16:30

Two new critical severity vulnerabilities have been discovered in the MegaRAC Baseboard Management Controller software made by hardware and software company American Megatrends International.

MegaRAC BMC provides admins with "Out-of-band" and "Lights-out" remote system management capabilities, enabling them to troubleshoot servers as if they were physically in front of the devices.

By combining these vulnerabilities, a remote attacker with network access to the BMC management interface and lacking BMC credentials can gain remote code execution on servers running vulnerable firmware.

In December 2022 and January 2023, Eclypsium disclosed five more MegaRAC BMC vulnerabilities that could be exploited to hijack, brick, or remotely infect compromised servers with malware.

Critical ColdFusion flaws exploited in attacks to drop webshells.

Hackers exploiting critical WordPress WooCommerce Payments bug.


News URL

https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bugs-can-let-hackers-brick-vulnerable-servers/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
AMI 5 0 6 30 6 42