返回全部动态

研究揭示服务器BMC存在大量未修复漏洞,可被远程后门利用

原标题:Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Ars Technica AI安全质量 71

AI 摘要

在周三的Black Hat安全会议上,runZero CEO HD Moore披露了HPE、Supermicro、Avocent、华为、联想、戴尔等厂商销售的服务器主板管理控制器(BMC)中存在十多个新漏洞,其中一些漏洞自2013年以来仍未修复。这些漏洞可被远程利用,使攻击者能够后门控制数千台服务器,构成严重的安全威胁。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday. Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, netw


发布时间:2026-08-06 06:35
抓取时间:2026-08-06 20:57
来源机构:Ars Technica
阅读原文arstechnica.com