AMI MegaRAC flaws affect many cloud service providers’ servers
By MYBRANDBOOK
Three vulnerabilities naming CVE-2022-40259, CVE-2022-40242 and CVE-2022-2827 in the American Megatrends MegaRAC Baseboard Management Controller (BMC) software impact server equipment used in many cloud service and data center providers.
The flaws could enable attackers to execute code, bypass authentication, and perform user enumeration. The first two flaws are very severe due to giving attackers access to an administrative shell without requiring further escalation.
The most severe of the three flaws, CVE-2022-40259, requires prior access to at least a low-privileged account to perform the API call-back. The vulnerabilities could cause data manipulation, data breaches, service outage, business interruption, and more.
MegaRAC BMC firmware is used by at least 15 server manufacturers, including AMD, Ampere Computing, ASRock, Asus, ARM, Dell EMC, Gigabyte, Hewlett-Packard Enterprise, Huawei, Inspur, Lenovo, Nvidia, Qualcomm, Quanta, and Tyan.
System admins are advised to disable remote administration options and add remote authentication steps where possible. Additionally, they should minimize the external exposure of server management interfaces like Redfish and ensure that the latest available firmware updates are installed on all systems.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
ICONS OF INDIA : SANJAY GUPTA
Sanjay Gupta is the Country Head and Vice President of Google India an...
Icons Of India : RAJENDRA SINGH PAWAR
Rajendra Singh Pawar is the Executive Chairman and Co-Founder of NIIT ...
ICONS OF INDIA : SUNIL VACHANI
Sunil Vachani is the Chairman of Dixon Technologies (India) Ltd. Under...
DRDO - Defence Research and Development Organisation
DRDO responsible for the development of technology for use by the mili...
CERT-IN - Indian Computer Emergency Response Team
CERT-In is a national nodal agency for responding to computer security...
IREDA - Indian Renewable Energy Development Agency Limited
IREDA is a specialized financial institution in India that facilitates...
Indian Tech Talent Excelling The Tech World - Aman Bhutani, CEO, GoDaddy
Aman Bhutani, the self-taught techie and CEO of GoDaddy, oversees a co...
Indian Tech Talent Excelling The Tech World - Shantanu Narayen, CEO- Adobe Systems Incorporated
Shantanu Narayen, CEO of Adobe Systems Incorporated, is renowned for h...
Indian Tech Talent Excelling The Tech World - Dheeraj Pandey, CEO, DevRev
Dheeraj Pandey, Co-founder and CEO at DevRev , has a remarkable journe...