Actively exploited vulnerability gives extraordinary control over server fleets
Actively exploited vulnerability gives extraordinary control over server fleets

arstechnica.com
Actively exploited vulnerability gives extraordinary control over server fleets

The vulnerability, carrying a severity rating of 10 out of a possible 10, resides in the AMI MegaRAC, a widely used firmware package that allows large fleets of servers to be remotely accessed and managed even when power is unavailable or the operating system isn't functioning. These motherboard-attached microcontrollers, known as baseboard management controllers (BMCs), give extraordinary control over servers inside data centers.