Insecure virtual USB feature in Supermicro BMCs exposes servers to attack

Insecure virtual USB feature in Supermicro BMCs exposes servers to attack

A baseband management controller (BMC) is an independent microcontroller present on server motherboards that allows out-of-band management of those servers. BMCs are like small computers with their own specialized firmware that run inside, but independently of the main computer -- the server itself. The BMC software is typically unique for every server manufacturer, and it presents a management interface that gives administrators full control over the server and its operating system.

The level of access that BMC interfaces provide make them highly powerful, which is why the security of BMC implementations has been scrutinized for years, and researchers have found various types of vulnerabilities affecting servers from different manufacturers.

To read this article in full, please click here



Support the originator by clicking the read the rest link below.