Intel Corporation on the elimination of 22 vulnerabilities in the firmware of their server motherboards, server systems, and compute modules. Three vulnerabilities, one of which has been assigned a critical level, ( — CVSS 9.6, — CVSS 8.3, — CVSS 4.7) in the firmware of the Emulex Pilot 3 BMC controller used in Intel products. The vulnerabilities allow unauthenticated access to the remote management console (KVM), bypass authentication when emulating USB storage devices, and trigger a remote buffer overflow in the Linux kernel used in BMC.
The CVE-2020-8708 vulnerability enables an unauthenticated attacker with access to the same local network segment as the vulnerable server to gain access to the BMC management environment. It is noted that the exploitation technique for this vulnerability is very simple and reliable, as the issue stems from an architectural flaw. Moreover, according to the researcher who discovered the vulnerability, working with BMC through the exploit is much more convenient than using the standard Java client. Among the affected equipment are server system families Intel R1000WT, R2000WT, R1000SP, LSVRP, LR1304SP, R1000WF, and R2000WF, motherboards S2600WT, S2600CW, S2600KP, S2600TP, S1200SP, S2600WF, S2600ST, and S2600BP, as well as compute modules HNS2600KP, HNS2600TP, and HNS2600BP. The vulnerabilities have been fixed in firmware update 1.59.
According to unofficial the firmware for BMC Emulex Pilot 3 was written by AMI, so The issues exist in external patches to the Linux kernel and the user-space management process, the code of which has been characterized by the researcher who identified the issue as the worst code he has encountered.
Note that BMC is a dedicated controller installed in servers, with its own CPU, memory, storage, and sensor polling interfaces, providing a low-level interface for monitoring and managing server hardware. Using BMC, the state of sensors can be monitored, power management, firmware, and disks can be controlled, remote network booting can be organized, and remote access console functionality can be provided, regardless of the operating system running on the server.
Source: opennet.ru
