Researchers disclose vulnerabilities in IP KVMs from four manufacturers



Researchers are warning about the risks posed by a low-cost device that can give insiders and hackers unusually broad powers in compromising networks.

The devices, which typically sell for $30 to $100, are known as IP KVMs. Administrators often use them to remotely access machines on networks. The devices, not much bigger than a deck of cards, allow the machines to be accessed at the BIOS/UEFI level, the firmware that runs before the loading of the operating system.

This provides power and convenience to admins, but in the wrong hands, the capabilities can often torpedo what might otherwise be a secure network. Risks are posed when the devices—which are exposed to the Internet—are deployed with weak security configurations or surreptitiously connected to by insiders. Firmware vulnerabilities also leave them open to remote takeover.

No exotic zero-days here

On Tuesday, researchers from security firm Eclypsium disclosed a total of nine vulnerabilities in IP KVMs from four manufacturers. The most severe flaws allow unauthenticated hackers to gain root access or run malicious code on them.

“These are not exotic zero-days requiring months of reverse engineering,” Eclypsium researchers Paul Asadoorian and Reynaldo Vasquez Garcia wrote. “These are fundamental security controls that any networked device should implement. Input validation. Authentication. Cryptographic verification. Rate limiting. We are looking at the same class of failures that plagued early IoT devices a decade ago, but now on a device class that provides the equivalent of physical access to everything it connects to.”



Source link

  • Related Posts

    Dyson’s New PencilWash Is Here

    Welcome to a new world of mopping options from Dyson. After announcing several new models last year at IFA Berlin, Dyson has begun rolling out its latest suite of vacuums…

    Kagi brings its ‘small web’ of a human-only internet to mobile devices

    As AI takes over the internet, Palo Alto-based search engine Kagi is bringing its handpicked collection of non-commercial, human-authored websites to mobile devices through new “Small Web” apps for iOS…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    'Outcome' Trailer

    'Outcome' Trailer

    Demi Lovato Cuts Through Midtown in Satin Slingbacks

    Demi Lovato Cuts Through Midtown in Satin Slingbacks

    Israel Keeps Killing Key Iranian Leaders. Will It Work?

    In Their Words: How Gregory Bovino became a face of Trump’s mass deportations and ended his career

    In Their Words: How Gregory Bovino became a face of Trump’s mass deportations and ended his career

    Australia news live: Trump lashes out at Australia over absence of allies against Iran; Cyclone Narelle forms in Coral Sea | Australia news

    Australia news live: Trump lashes out at Australia over absence of allies against Iran; Cyclone Narelle forms in Coral Sea | Australia news

    Current welcome offers on One Key credit cards

    Current welcome offers on One Key credit cards