Researchers disclose vulnerabilities in IP KVMs from four manufacturers



Researchers are warning about the risks posed by a low-cost device that can give insiders and hackers unusually broad powers in compromising networks.

The devices, which typically sell for $30 to $100, are known as IP KVMs. Administrators often use them to remotely access machines on networks. The devices, not much bigger than a deck of cards, allow the machines to be accessed at the BIOS/UEFI level, the firmware that runs before the loading of the operating system.

This provides power and convenience to admins, but in the wrong hands, the capabilities can often torpedo what might otherwise be a secure network. Risks are posed when the devices—which are exposed to the Internet—are deployed with weak security configurations or surreptitiously connected to by insiders. Firmware vulnerabilities also leave them open to remote takeover.

No exotic zero-days here

On Tuesday, researchers from security firm Eclypsium disclosed a total of nine vulnerabilities in IP KVMs from four manufacturers. The most severe flaws allow unauthenticated hackers to gain root access or run malicious code on them.

“These are not exotic zero-days requiring months of reverse engineering,” Eclypsium researchers Paul Asadoorian and Reynaldo Vasquez Garcia wrote. “These are fundamental security controls that any networked device should implement. Input validation. Authentication. Cryptographic verification. Rate limiting. We are looking at the same class of failures that plagued early IoT devices a decade ago, but now on a device class that provides the equivalent of physical access to everything it connects to.”



Source link

  • Related Posts

    DoorDash Reservations Scored America’s Most Exclusive Restaurants

    At The Eighty-Six in Manhattan, exclusivity is the point. The luxe, 11-table steakhouse is the sort of place that lavishes caviar and aged mimolette cheese on its potatoes, and crows…

    Kalshi’s legal troubles pile up, as Arizona files first ever criminal charges over ‘illegal gambling business’

    Arizona Attorney General Kris Mayes has filed criminal charges against prediction market platform Kalshi, for allegedly operating an illegal gambling business in the state without a license and for election…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Ali Larijani, a Top Iranian Politician and Emissary, Is Dead at 67

    Why Ross Chastain just doesn’t get along with Daniel Suarez

    Why Ross Chastain just doesn’t get along with Daniel Suarez

    Maintenance Fire Leads To First Airbus A220 Hull Loss

    Maintenance Fire Leads To First Airbus A220 Hull Loss

    Not getting involved – iPolitics

    Not getting involved – iPolitics

    Police anticipated ‘worst-case scenario’ by deploying sniper at St. Patrick’s Day party, says former officer

    Police anticipated ‘worst-case scenario’ by deploying sniper at St. Patrick’s Day party, says former officer

    ‘Blue Heron’ Trailer | Moviefone

    ‘Blue Heron’ Trailer | Moviefone