Home SECURITY The main board management controller is a vulnerable spot for hacker attacks

The main board management controller is a vulnerable spot for hacker attacks

0
The main board management controller is a vulnerable spot for hacker attacks

[ad_1]

The main board management controller is a vulnerable spot for hacker attacks

The CISA and NSA have made recommendations for protecting BMCs from attackers who might use them as entry points.

US cybersecurity agencies CISA And NSA stated in their recent joint leadership that the baseboard control controllers (BMC) is a weak link in critical infrastructure systems that can be exploited by attackers to gain access to networks and data.

BMC makes it possible to remotely manage and control computers and servers even when the system is turned off. However, due to their high level of privilege and accessibility from the network, these devices often attract the attention of attackers who can use them as an entry point for various cyber attacks.

The CISA and NSA guidance contains recommendations and mitigations for vulnerabilities in the BMC, such as credential protection, firmware upgrades, VLAN separation, and integrity monitoring. In addition, agencies advise moving highly sensitive production data to secure devices, as well as periodically using firmware scanning tools and considering unused BMCs as potential security risks.

“By following these guidelines, organizations can significantly improve the security of their BMCs and reduce the risk of potential cyber threats,” the document says.

The new guidelines come weeks after the UK’s National Cyber ​​Security Center (NCSC) and other international security agencies released new warning warning the public against Chinese cyber activity targeting critical national infrastructure networks in the United States.

“We encourage all server management organizations to implement the recommended actions in this guide,” said Jennifer Esterly, director of CISA.

[ad_2]

Source link

www.securitylab.ru

LEAVE A REPLY

Please enter your comment!
Please enter your name here