Vulnerability in BMC controller firmware affecting servers from many manufacturers

Eclypsium ujawnili Two vulnerabilities in the BMC controller firmware supplied in Lenovo ThinkServer servers allow a local user to replace the firmware or execute arbitrary code on the BMC chip.

Further analysis revealed that these issues also affect BMC controller firmware used in Gigabyte Enterprise Servers, which are also utilized in servers from companies such as Acer, AMAX, Bigtera, Ciara, Penguin Computing, and sysGen. The problematic BMC controllers used vulnerable MergePoint EMS firmware developed by a third-party supplier, Avocent (now a division of Vertiv).

The first vulnerability is caused by the lack of cryptographic verification of loaded firmware updates (only CRC32 checksum verification is used, contrary to zaleceń NIST's use of digital signatures), allowing an attacker with local access to the system to replace the BMC firmware. This issue can be exploited for deep integration of a rootkit that remains active after the operating system is reinstalled and blocks further firmware updates (removing the rootkit requires the use of a programmer to overwrite SPI flash).

The second vulnerability lies in the firmware update code and allows the substitution of commands that will be executed in the BMC with the highest privilege level. To carry out the attack, it is sufficient to change the value of the RemoteFirmwareImageFilePath parameter in the bmcfwu.cfg configuration file, which defines the path to the firmware image being updated. During the next update, which can be initiated by a command in IPMI, this parameter will be processed by the BMC and used in the popen() call as part of the string for /bin/sh. Since the string for forming the shell command is created using snprintf() without proper special character cleaning, attackers can inject their code for execution. Exploiting this vulnerability requires permissions to send a command to the BMC controller through IPMI (if the server has administrator rights, an IPMI command can be sent without additional authentication).

Firmy Gigabyte i Lenovo zostały poinformowane o problemach już w lipcu 2018 roku i zdążyły wydać aktualizacje przed publicznym ujawnieniem informacji. Firma Lenovo wydała wydała aktualizacje oprogramowania 15 listopada 2018 roku dla serwerów ThinkServer RD340, TD340, RD440, RD540 i RD640, ale usunęła w nich jedynie podatność umożliwiającą wstrzykiwanie poleceń, ponieważ podczas tworzenia linii serwerów opartych na MergePoint EMS w 2014 roku weryfikacja oprogramowania za pomocą podpisu cyfrowego nie była jeszcze powszechnie stosowana i nie była pierwotnie deklarowana.

8 maja tego roku firma Gigabyte wydała aktualizacje oprogramowania dla płyt głównych z kontrolerem ASPEED AST2500, ale podobnie jak Lenovo usunęła jedynie podatność związaną z wstrzykiwaniem poleceń. Podatne płyty oparte na ASPEED AST2400 nadal nie mają aktualizacji. Gigabyte również stwierdził przejdzie na korzystanie z oprogramowania MegaRAC SP-X od firmy AMI. Nowe oprogramowanie oparte na MegaRAC SP-X będzie również oferowane dla systemów, które wcześniej były dostarczane z oprogramowaniem MergePoint EMS. Decyzja ta została podjęta po oświadczeniu Vertiv o zaprzestaniu wsparcia dla platformy MergePoint EMS. Na razie nie ma informacji o aktualizacji oprogramowania dla serwerów produkowanych przez firmy Acer, AMAX, Bigtera, Ciara, Penguin Computing i sysGen, które są oparte na płytach Gigabyte i wykorzystują podatne wersje oprogramowania MergePoint EMS.

Przypominamy, że BMC to specjalizowany kontroler instalowany w serwerach, który posiada własny CPU, pamięć, przechowywanie i interfejsy do monitorowania sensorów, zapewniający niski poziom dostępu do monitorowania i zarządzania sprzętem serwerowym. Dzięki BMC, niezależnie od działającego na serwerze systemu operacyjnego, można monitorować stan sensorów, zarządzać zasilaniem, oprogramowaniem i dyskami, zorganizować zdalne uruchamianie przez sieć, zapewnić działanie konsoli zdalnego dostępu itd.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster