2 ms·
For one thing a lot of BMCs are not the easiest to secure and at least KVM devices like a Spider or PiKVM can be patched so that these network accessible device
by devonkim 4y ago
For one thing a lot of BMCs are not the easiest to secure and at least KVM devices like a Spider or PiKVM can be patched so that these network accessible devices aren’t so easy to own remotely. A number of BMCs can start advertising and routing to itself across different PHY so even not hooking up the management NIC to a separate LAN won’t be enough then (you’d need to have the right settings and hope you can disable this behavior to avoid such a broadcast across other NICs). I have this issue with my ASRock ASpeed BMC and never got around to fixing it but it bothers me a bit every time I see the IP pop up in my DHCP list and ARP tables.
- _abox 4y agoBMCs can also be patched. HP updates iLO regularly. I even got a major update on my servers adding things like HTML5 consoles (previously it only had .NET and Java which is a pain in this day and age) And this is for a server I paid $150 for after cashback from HP.
- devonkim 4y agoOh yes, BMCs can certainly be patched but I had the security issue long after the last patch for the motherboard was released so it really comes down to the manufacturer support level as usual. HP likely does better than Supermicro which likely does better than ASRock