Tuesday, July 2, 2024

Intel and Lenovo BMCs Include Unpatched Lighttpd Server Flaw

Apr 15, 2024NewsroomFirmware Safety / Vulnerability

Intel and Lenovo BMCs

A safety flaw impacting the Lighttpd net server utilized in baseboard administration controllers (BMCs) has remained unpatched by system distributors like Intel and Lenovo, new findings from Binarly reveal.

Whereas the unique shortcoming was found and patched by the Lighttpd maintainers approach again in August 2018 with model 1.4.51, the dearth of a CVE identifier or an advisory meant that it was neglected by builders of AMI MegaRAC BMC, finally ending up in merchandise made by Intel and Lenovo.

Lighttpd (pronounced “Lighty”) is an open-source high-performance net server software program designed for pace, safety, and adaptability, whereas optimized for high-performance environments with out consuming numerous system assets.

The silent repair for Lighttpd issues an out-of-bounds learn vulnerability that might be exploited to exfiltrate delicate information, reminiscent of course of reminiscence addresses, thereby permitting menace actors to bypass essential safety mechanisms like deal with area format randomization (ASLR).

Cybersecurity

“The absence of immediate and necessary details about safety fixes prevents correct dealing with of those fixes down each the firmware and software program provide chains,” the firmware safety firm mentioned.

The issues are described under –

  • Out-of-bounds learn in Lighttpd 1.4.45 utilized in Intel M70KLP sequence firmware
  • Out-of-bounds learn in Lighttpd 1.4.35 utilized in Lenovo BMC firmware
  • Out-of-bounds learn in Lighttpd earlier than 1.4.51

Intel and Lenovo have opted to not deal with the problem because the merchandise incorporating the vulnerable model of Lighttpd have hit end-of-life (EoL) standing and are not eligible for safety updates, successfully turning it right into a forever-day bug.

Intel and Lenovo BMCs

The disclosure highlights how the presence of outdated third-party elements within the newest model of firmware can traverse the availability chain and pose unintended safety dangers for finish customers.

“That is one more vulnerability that may stay unfixed eternally in some merchandise and can current high-impact threat to the business for a really very long time,” Binarly added.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles