HomeSecuritySerious AMI MegaRAC vulnerabilities affect the servers of many companies

Serious AMI MegaRAC vulnerabilities affect servers of many companies

Three vulnerabilities in American Megatrends MegaRAC Baseboard Management Controller (BMC) software affect server equipment used by many cloud and data center service providers.

MegaRAC

See also: France: Hospital cancels operations due to cyberattack

In August 2022, Eclypsium discovered several bugs that could allow attackers, under certain circumstances, to execute code, bypass authentication, and perform user enumeration.

After researchers examined the leaked proprietary code from American Megatrends, they discovered several flaws in the MegaRAC BMC firmware.

With MegaRAC BMC, you can manage your servers remotely without having to be physically present. This is especially useful for troubleshooting purposes.

Some of the server manufacturers using the MegaRAC BMC firmware include AMD, Ampere Computing, ASRock, Asus, ARM, Dell EMC, Gigabyte, Hewlett-Packard Enterprise, Huawei, Inspur, Lenovo, Nvidia, Qualcomm, Quanta, and Tyan.

Vulnerability details

The three vulnerabilities discovered by Eclypsium and reported to American Megatrends and the affected vendors are as follows:

  • CVE-2022-40259: Redfish API arbitrary code execution flaw due to improper user command exposure. (CVSS v3.1 rating: 9.9 "critical")
  • CVE-2022-40242: Default credentials for the sysadmin user, allowing attackers to create an administrative shell. (CVSS v3.1 score: 8.3 “high”)
  • CVE-2022-2827: Request manipulation flaw that allows an attacker to enumerate usernames and determine whether an account exists. (CVSS v3.1 score: 7.5 “high”)

The most serious of the three flaws, CVE-2022-40259, requires prior access to at least one low-privilege account to execute the API callback.

Regarding CVE-2022-40242, all an attacker needs to do to exploit CVE-2022-40242 is to have remote access to the device.

See also: New CryWiper malware appears to be ransomware

MegaRAC

Impact

The first two flaws are very serious because they give attackers access to an administrative shell without requiring further escalation.

If these vulnerabilities are successfully exploited, they could cause data manipulation, service interruptions, data breaches, and more.

Although the third flaw does not have a direct impact on security, it could potentially cause damage, as knowing which accounts exist on the targeted system is not enough to cause any damage.

See also: USA – COVID-19 benefits: Chinese group APT41 stole them

To enhance security, system administrators should disable remote management options and incorporate additional authentication steps for remote access to systems.

Additionally, administrators should minimize external exposure of server management interfaces like Redfish and ensure that the latest available firmware updates are installed on all systems.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS