网站导航

ABB PFSK152 3BSE018877R2 厦门雄霸电子

当前位置:主页 > 产品展示 > ABB系统备件

ABB PFSK152 3BSE018877R2 厦门雄霸电子

型号: ABB PFSK152 3BSE018877R2

分类: ABB系统备件

联系人:何经理

手机:13313705507

QQ:2235954483

邮箱:2235954483@qq.com

地址:厦门市思明区吕岭路1733号万科创想中心2009室

详细介绍

这个名为IPMI的密码泄露漏洞是智能型平台管理接口(Intelligent Platform Management Interface)的缩写,是管理基于 Intel结构的企业系统中所使用的外围设备采用的一种工业标准,该标准由英特尔、惠普、NEC、美国戴尔电脑和SuperMicro等公司制定。IPMI是一种开放标准的硬件管理接口规格,定义了嵌入式管理子系统进行通信的特定方法。IPMI 信息通过基板管理控制器 (BMC)(位于 IPMI 规格的硬件组件上)进行交流。

 

  简单来说,有了IPMI这个东西,用户可以利用IPMI监视服务器的物理健康特征,如温度、电压、风扇工作状态、电源状态等,更重要的是可以装系统、开关机、查看操作服务器屏幕输出,就好比站在服务器面前。

 

  而IPMI是可以通过Web管理的,通过80端口进入管理界面,这里需要账户密码认证,而本次漏洞正是泄漏了这个认证的密码信息。

 

  山丽网安的专家提醒:这个密码泄露漏洞可以让攻击者不通过认证就可获得管理密码,一旦让黑客获取服务器的高权限,造成的严重后果可想而知。因此被该漏洞影响的所有服务器应尽快的联系厂家进行升级,为避免因漏洞带来的信息泄露后果,利用灵活且有针对性的加密软件将重要数据加密,有效阻止信息泄露。

 

 

 

 


ABB PFSK152 3BSE018877R2 厦门雄霸电子

This password leakage vulnerability called IPMI is the abbreviation for Intelligent Platform Management Interface, which is an industry standard used to manage peripheral devices used in Intel based enterprise systems. The standard was developed by companies such as Intel, HP, NEC, Dell computers, and SuperMicro in the United States. IPMI is an open standard hardware management interface specification that defines specific methods for communication between embedded management subsystems. IPMI information is communicated through the Baseboard Management Controller (BMC) (located on IPMI specification hardware components).
Simply put, with IPMI, users can use it to monitor the physical health characteristics of servers, such as temperature, voltage, fan operation status, power status, etc. More importantly, they can install the system, turn on/off, and view the output of the server screen, just like standing in front of the server.
And IPMI can be managed through the web, entering the management interface through port 80, where account password authentication is required, and this vulnerability precisely leaks the password information of this authentication.
Experts from Shanli Wangan remind that this password leakage vulnerability can allow attackers to obtain management passwords without authentication. Once hackers gain high privileges on the server, the serious consequences can be imagined. Therefore, all servers affected by this vulnerability should contact the manufacturer as soon as possible to upgrade. To avoid the consequences of information leakage caused by the vulnerability, flexible and targeted encryption software should be used to encrypt important data, effectively preventing information leakage.

 

ABB PFSK152 3BSE018877R2 厦门雄霸电子


推荐产品

如果您有任何问题,请跟我们联系!

联系我们

Copyright © 2002-2020 厦门雄霸电子商务有限公司 版权所有

闽公网安备 35020302034927号

备案号:闽ICP备14012685号

地址:厦门市思明区吕岭路1733号万科创想中心2009室

在线客服 联系方式 二维码

服务热线

13313705507

扫一扫,关注我们