Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Records Worst Performance For June, Will It Get Better From Here? bitcoin news
  • Musk and Goldman Sachs’ Blankfein Weigh In; Galaxy Digital’s CEO Talks on Terra Collapse — Bitcoin.com News Week in Review – The Weekly Bitcoin News bitcoin news
  • Bored Ape and Cryptopunk Values Wobble — During the Last Month, Blue-Chip NFT Floor Values Dropped Over 50% – Markets and Prices Bitcoin News bitcoin news
  • Ethereum Shows Positive Signs But This Resistance Is The Key bitcoin news
  • Lawsuit Accuses Binance US of Selling Unregistered Securities, False Advertising Terra UST as ‘Safe’ – Bitcoin News bitcoin news
  • Here’s How to Purchase Your First NFT Domain on Quik․com – Sponsored Bitcoin News bitcoin news
  • Cryptocurrencies Unlikely to Help Russia Evade Sanctions – Bitcoin News bitcoin news
  • Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums cyber security news

Critical ‘Pantsdown’ BMC Vulnerability Affects QCT Servers Used in Data Centers

Posted on May 26, 2022 By root


BMC Vulnerability

Quanta Cloud Technology (QCT) servers have been identified as vulnerable to the severe “Pantsdown” Baseboard Management Controller (BMC) flaw, according to new research published today.

“An attacker running code on a vulnerable QCT server would be able to ‘hop’ from the server host to the BMC and move their attacks to the server management network, possibly continue and obtain further permissions to other BMCs on the network and by doing that gaining access to other servers,” firmware and hardware security firm Eclypsium said.

A baseboard management controller is a specialized system used for remote monitoring and management of servers, including controlling low-level hardware settings as well as installing firmware and software updates.

CyberSecurity

Tracked as CVE-2019-6260 (CVSS score: 9.8), the critical security flaw came to light in January 2019 and relates to a case of arbitrary read and write access to the BMC’s physical address space, resulting in arbitrary code execution.

Successful exploitation of the vulnerability can provide a threat actor with full control over the server, making it possible to overwrite the BMC firmware with malicious code, deploy persistent malware, exfiltrate data, and even brick the system.

Impacted QCT server models include D52BQ-2U, D52BQ-2U 3UPI, D52BV-2U, which come with BMC version 4.55.00 that runs a version of BMC software vulnerable to

Pantsdown. Following responsible disclosure on October 7, 2021, a patch has been made privately available to customers on April 15.

The fact that a three-year-old weakness still continues to exist underscores the need to fortify firmware-level code by applying updates in a timely fashion and regularly scanning the firmware for potential indicators of compromise.

CyberSecurity

Firmware security is particularly crucial in light of the fact that components like BMC have emerged as a lucrative target of cyberattacks aimed at planting stealthy malware such as iLOBleed that’s designed to completely wipe a victim server’s disks.

To mitigate such risks, it’s reminded that organizations relying on QCT products should verify the integrity of their BMC firmware and update the component to the latest version as and when the fixes become available.

“Adversaries are getting increasingly comfortable wielding firmware-level attacks,” the company said. “What is important to note is how knowledge of firmware-level exploits has increased over the years: what was difficult in 2019 is almost trivial today.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: ETH Hits 2-Week Low, Following Move Below $1,900 – Market Updates Bitcoin News
Next Post: Ethereum’s Beacon Network Deals With a 7-Block Chain Reorganization – Bitcoin News

Related Posts

  • Zyxel Issues Patches for 4 New Flaws Affecting AP, API Controller and Firewall Devices cyber security news
  • New ‘GoodWill’ Ransomware Forces Victims to Donate Money and Clothes to the Poor cyber security news
  • Google’s New Safety Section Shows What Data Android Apps Collect About Users cyber security news
  • How to Improve Margins and Scale-Up Service Delivery cyber security news
  • A New Android Banking Trojan Spotted in the Wild cyber security news
  • Are You Investing in Securing Your Data in the Cloud? cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Cardano (ADA) Grapples At $0.524; Bullish Trajectory Coming bitcoin news
  • APT Hackers Targeting Industrial Control Systems with ShadowPad Backdoor cyber security news
  • Why Ethereum Could Trade At $500 If These Conditions Are Met bitcoin news
  • Banco Galicia Becomes First Bank to Introduce Crypto Trading in Argentina – Bitcoin News bitcoin news
  • Bitcoin Perpetual Open Interest Suggests Short Squeeze Led To Crash bitcoin news
  • Goldman Sachs Sees Higher US Recession Risk Citing Concerns the Fed Will ‘Respond Forcefully’ to High Inflation – Economics Bitcoin News bitcoin news
  • Choise.com Announces Listing of In-platform CHO Token on Uniswap bitcoin news
  • Belgium Introduces Registration for Crypto Exchange and Wallet Service Providers – Regulation Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme