Older Intel and Lenovo Hardware Has Hackable Firmware Bugs That Will Never Be Fixed, Researchers Find

Spread the love


Some Intel and Lenovo merchandise and options have an unfixable bug of their firmware that would let the tools to be hacked. The bug in concern has sat unpatched for a number of years and can by no means ever be patched primarily as a result of the impacted objects have been thought-about “end-of-life” and won’t obtain any further pc software program updates. Whereas the vulnerability is main loads of to make it potential for a unfavorable actor to chain it to a way more refined exploit, it doesn’t, by itself, present considerably of a hazard.

This week, the protection group Binarly launched a report concerning the security issues, which revolve all-around Lighttpd—a versatile, open up-supply web site server that’s utilized in myriad tech merchandise, along with firmware parts. A number of years in the past, within the summertime of 2018, a remotely exploitable software vulnerability was discovered inside Lighttpd by its maintainers that would have hypothetically allowed a savvy cybercriminal to entry vital security info and info.

Lighttpd’s software program program maintainers quietly issued a care for of their private code, Binarly researchers said, however they didn’t formalize it through a CVE—a standard vulnerabilities and exposures identifier—which might have permitted companies using the appliance to appropriate the issue. Lighttpd is utilised in numerous objects, which incorporates all these developed by American Megatrends Worldwide (AMI), a agency that generates considerably of the firmware software that essential suppliers depend on.

The trickle-down result’s that specific types of {hardware}—together with a number of merchandise made by Lenovo and Intel—by no means bought the cope with and, for that cause, are even now inclined to the bug. Now, individuals impacted devices will by no means ever be mounted, Binarly scientists declare, as a result of their distributors aren’t pushing out program updates for them anymore.

See also  Amazon's Fire HD 10 tablet drops to a record-low price ahead of October Prime Day

When reached for remark, Lenovo said it’s “conscious of the AMI MegaRAC concern recognized by Binarly” and that it’s “working with our provider to ascertain any potential impacts to Lenovo merchandise and options.” Intel, within the meantime, defined that the “affected system is for the time being finish-of-daily life, meaning no practical, security, or different updates will likely be supplied.”

Ars Technica notes that “the severity of the lighttpd vulnerability is just reasonable and is of no value except an attacker has a functioning exploit for a a lot further extreme vulnerability.” Binarly researchers have talked about {that a} “potential attacker can exploit this vulnerability in an effort to learn by way of reminiscence of Lighttpd World large internet Server plan of action,” which may result in “delicate info exfiltration, these sorts of as reminiscence addresses” and “can be utilized to bypass safety mechanisms this sort of as ASLR.” For that cause, the bug would floor to be way more of a leaping-off place for a much more subtle assault, even supposing it plainly presents a possibility for intrusion and, sooner or later, compromise.

best barefoot shoes

Supply website link

  • David Bridges

    David Bridges

    David Bridges is a media culture writer and social trends observer with over 15 years of experience in analyzing the intersection of entertainment, digital behavior, and public perception. With a background in communication and cultural studies, David blends critical insight with a light, relatable tone that connects with readers interested in celebrities, online narratives, and the ever-evolving world of social media. When he's not tracking internet drama or decoding pop culture signals, David enjoys people-watching in cafés, writing short satire, and pretending to ignore trending hashtags.

    Related Posts

    iRacing on Vision Pro Requires a Powerful PC to Play

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI iRacing iRacing has officially launched its immersive racing simulator on the Apple Vision Pro headset. This exciting…

    Read more

    VisionQuest Premieres on Disney+ This October

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI WandaVision, which marked the inaugural television series of the Marvel Cinematic Universe available on Disney+, premiered its…

    Read more

    You Missed

    Prodentim Reviews: Customer Feedback, User Results & Oral Health Benefits

    Prodentim Reviews: Customer Feedback, User Results & Oral Health Benefits

    Funeral Photos of 8 Children Victims of Shamar Elkins

    Funeral Photos of 8 Children Victims of Shamar Elkins

    iRacing on Vision Pro Requires a Powerful PC to Play

    iRacing on Vision Pro Requires a Powerful PC to Play

    Jamie Foxx May Welcome Newborn to His Family Gang! 👀

    Jamie Foxx May Welcome Newborn to His Family Gang! 👀

    Instagram Turns Off Ultra Private Direct Messaging Features

    Instagram Turns Off Ultra Private Direct Messaging Features

    Smarter Online Registration: NeedTags Begins a New Chapter

    Smarter Online Registration: NeedTags Begins a New Chapter

    VisionQuest Premieres on Disney+ This October

    VisionQuest Premieres on Disney+ This October

    John Candy: I Like Me – Tyler Strickland’s Musical Triumphs

    John Candy: I Like Me – Tyler Strickland’s Musical Triumphs

    Chrisean Rock Responds to Viral Blueface Videos

    Chrisean Rock Responds to Viral Blueface Videos

    Spotify outage confirmed by music streamer on X (updated)

    Spotify outage confirmed by music streamer on X (updated)