A vulnerability in the firmware of BMC controllers affecting servers from many manufacturers.

Eclypsium has identified two vulnerabilities in the firmware of the BMC controller supplied with Lenovo ThinkServer servers, allowing a local user to modify the firmware or execute arbitrary code on the BMC chip.

Further analysis revealed that these issues also affect the firmware of BMC controllers used in Gigabyte Enterprise Servers, which are also utilized in servers from companies such as Acer, AMAX, Bigtera, Ciara, Penguin Computing, and sysGen. The problematic BMC controllers incorporated vulnerable MergePoint EMS firmware developed by the third-party vendor Avocent (now a subsidiary of Vertiv).

The first vulnerability is caused by the absence of cryptographic verification for the firmware updates being loaded (only CRC32 checksum verification is used, contrary to recommendations NIST guidelines to use digital signatures), allowing an attacker with local access to the system to replace the BMC firmware. This issue, for example, could be exploited for deep rootkit integration, remaining active even after the operating system is reinstalled and blocking further firmware updates (to eliminate the rootkit, a programmer is required to rewrite the SPI flash).

The second vulnerability exists in the firmware update code and allows for the substitution of commands that will be executed in the BMC with the highest privilege level. To carry out the attack, it is sufficient to alter the value of the RemoteFirmwareImageFilePath parameter in the bmcfwu.cfg configuration file, which defines the path to the firmware image being updated. During the next update, which can be initiated with a command in IPMI, this parameter will be processed by the BMC and used in the popen() call as part of the string for /bin/sh. Since the shell command string is formed using the snprintf() call without proper sanitization of special characters, attackers can inject their code for execution. Exploitation of this vulnerability requires permissions that allow sending an IPMI command to the BMC controller (if admin rights on the server are present, an IPMI command can be sent without additional authentication).

Gigabyte and Lenovo were notified of the issues back in July 2018 and managed to release updates before the public disclosure of information. Lenovo released released firmware updates on November 15, 2018, for ThinkServer RD340, TD340, RD440, RD540, and RD640 servers, but only addressed the vulnerability allowing command injection, as digital signature verification for firmware was not widely implemented and was not initially declared when the server line based on MergePoint EMS was created in 2014.

On May 8 of this year, Gigabyte released firmware updates for motherboards with the ASPEED AST2500 controller, but like Lenovo, only fixed the command injection vulnerability. Vulnerable boards based on the ASPEED AST2400 remain without updates for now. Gigabyte also announced announced a transition to using MegaRAC SP-X firmware from AMI. New firmware based on MegaRAC SP-X will also be offered for systems previously shipped with MergePoint EMS firmware. This decision was made following Vertiv's announcement of the end of support for the MergePoint EMS platform. There are no updates mentioned yet for the servers produced by Acer, AMAX, Bigtera, Ciara, Penguin Computing, and sysGen based on Gigabyte boards and equipped with vulnerable MergePoint EMS firmware.

Note that BMC is a dedicated controller installed in servers, with its own CPU, memory, storage, and sensor polling interfaces, providing a low-level interface for monitoring and managing server hardware. Using BMC, the state of sensors can be monitored, power management, firmware, and disks can be controlled, remote network booting can be organized, and remote access console functionality can be provided, regardless of the operating system running on the server.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster