"Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw"
"Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw"
According to Binarly, there is an unpatched security flaw impacting the Lighttpd web server in Intel and Lenovo Baseboard Management Controllers (BMCs). Although the original flaw was discovered and patched by Lighttpd maintainers in August 2018 with version 1.4.51, the lack of a CVE identifier or advisory has caused it to be overlooked by AMI MegaRAC BMC developers. It has made its way into products made by Intel and Lenovo.