ended3월 17일· 1 sources

Researchers disclose vulnerabilities in IP KVMs from four manufacturers

4개 제조사의 IP KVM 장비에서 다수의 보안 취약점 공개

Why it matters

Security researchers from Eclypsium disclosed nine vulnerabilities in IP KVM devices from four manufacturers, with the most severe allowing unauthenticated root access or remote code execution. These low-cost ($30–$100) devices give remote BIOS/UEFI-level access to networked machines, making them high-value targets when exposed to the internet with weak configurations or unpatched firmware. The researchers noted the flaws stem from basic security failures—missing input validation, authentication, and cryptographic verification—mirroring issues that plagued early IoT devices.

1
Sources
+0
24h
Growth
188d
Active
IP KVMEclypsiumfirmware vulnerabilitiesBIOS/UEFIIoT security

Sources

Related Issues