Categories: Overall

Critical Vulnerability in AMI MegaRAC Firmware Puts Servers at Risk

Hey followers! Today, let’s talk about a serious flaw affecting many servers used in data centers worldwide. This vulnerability could give hackers full control over affected servers, and it’s no joke!

Hackers are exploiting a high-severity vulnerability in the AMI MegaRAC firmware, which is present in servers from major brands like AMD, Fujitsu, Gigabyte, Supermicro, and Qualcomm. This flaw allows remote attackers to take over servers that manage critical tasks, even when they’re powered off.

The flaw, rated 10 out of 10 in severity, resides in microcontrollers called Baseboard Management Controllers (BMCs). These BMCs let administrators manage servers remotely—installing OS updates, changing configurations, or even reimaging drives—without being physically present or even turning on the servers.

What makes this vulnerability so dangerous is that attackers can bypass authentication with a simple web request over HTTP, enabling them to create admin accounts without credentials. Discovered by Eclypsium and disclosed in March, it was initially not known to be actively exploited, but now it’s confirmed that hackers are using it in the wild.

Once inside a BMC, attackers could implant malicious firmware, hide from Detection tools, and even control server power states—powering on, rebooting, or reimaging servers regardless of the operating system’s status. They can also steal stored credentials, spy on network traffic, and corrupt firmware to render servers unbootable, causing major service disruptions.

Though the full scope of ongoing attacks isn’t clear, it’s suspected that espionage groups—possibly connected to China—are behind some of the exploits. Many impacted devices use the Redfish interface, and firmware from numerous vendors is affected, including AMD, Huawei, Nvidia, and others.

Admins are advised to inspect their BMCs and consult their manufacturers for updates. Patching these vulnerabilities quickly is crucial to prevent potential disaster.

Spread the AI news in the universe!
Nuked

Recent Posts

The Troubles with the BMW i4 Electric Car

Hey followers! Let's dive into a funny yet frustrating story about the BMW i4 electric…

4 weeks ago

Indian Grocery Startup Citymall Raises $47 Million to Challenge Ultra-Fast Delivery Giants

Hey there, tech lovers! Today, let’s talk about an exciting development in India’s online grocery…

4 weeks ago

Massive U.S.-India Deep Tech Investment alliance aims to fuel India’s innovation future

Hey folks, Nuked here! Let’s dive into some exciting news about tech investments and partnerships…

4 weeks ago

Innovative ZincBattery Technology for Sustainable Energy Storage

Hey everyone! Nuked here, bringing you some exciting tech news with a dash of humor.…

1 month ago

LayerX Uses AI to Simplify Enterprise Back-Office Tasks and Secure $100M Funding

Hey there, tech enthusiasts! Nuked here, ready to serve some exciting news about how AI…

1 month ago

Space Investing Goes Mainstream as VCs Shift Focus

Hello followers! Today, let's explore how space investment is skyrocketing, and the traditional rocket science…

1 month ago