Summary:
Two critical severity vulnerabilities, CVE-2023-34329 and CVE-2023-34330, have been discovered in the MegaRAC Baseboard Management Controller (BMC) software developed by American Megatrends International. This firmware is used by various server manufacturers, including AMD, Asus, Dell EMC, Lenovo, and others, who provide equipment to cloud service and data center providers. The security flaws allow attackers to bypass authentication and inject malicious code through Redfish remote management interfaces that are exposed to remote access. CVE-2023-34329 enables authentication bypass via HTTP header spoofing, while CVE-2023-34330 allows code injection through the Dynamic Redfish Extension interface. When combined, these vulnerabilities grant remote attackers with network access to the BMC management interface the ability to execute code on servers running vulnerable firmware, even without BMC credentials.[/subscribe_to_unlock_form]
Summary:
Two critical severity vulnerabilities, CVE-2023-34329 and CVE-2023-34330, have been discovered in the MegaRAC Baseboard Management Controller (BMC) software developed by American Megatrends International. This firmware is used by various server manufacturers, including AMD, Asus, Dell EMC, Lenovo, and others, who provide equipment to cloud service and data center providers. The security flaws allow attackers to bypass authentication and inject malicious code through Redfish remote management interfaces that are exposed to remote access. CVE-2023-34329 enables authentication bypass via HTTP header spoofing, while CVE-2023-34330 allows code injection through the Dynamic Redfish Extension interface. When combined, these vulnerabilities grant remote attackers with network access to the BMC management interface the ability to execute code on servers running vulnerable firmware, even without BMC credentials.[emaillocker id="1283"]
The impact of exploiting these vulnerabilities is severe and includes remote control of compromised servers, remote deployment of malware and ransomware, and potential physical damage to servers, including bricking motherboard components. Attackers can also cause indefinite reboot loops that victim organizations cannot interrupt. One of the previously disclosed vulnerabilities (CVE-2022-40258) involving weak password hashes for Redfish & API could aid attackers in cracking administrator passwords for the BMC chip, making the attack process more straightforward. As of their report, there was no evidence of these vulnerabilities being exploited in the wild. However, since threat actors have access to the stolen source data, there is a significant risk of these vulnerabilities being weaponized in the future.
Recommendations:
References:
The following reports contain further technical details:
[/emaillocker]