Why are BMCs hard to patch, and what happens when AI-assisted research uncovers an N-day vulnerability? Tod Beardsley breaks down the rediscovery of CVE-2024-38508 (root privilege escalation in Lenovo

Why are BMCs hard to patch, and what happens when AI-assisted research uncovers an N-day vulnerability? Tod Beardsley breaks down the rediscovery of CVE-2024-38508 (root privilege escalation in Lenovo XCC2 firmware) from runZero’s LightsOut project presented at Black Hat and DEF CON. Key insights: ✅️ BMC patching and downtime challenges ✅️ Technical breakdown of the bug ✅️ Finding affected devices

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Why are BMCs hard to patch, and what happens when AI-assisted research uncovers an N-day vulnerability? Tod Beardsley breaks down the rediscovery of CVE-2024-38508 (root privilege escalation in Lenovo

mastodon:infosec-exchangeother6d ago kagi ↗

Why are BMCs hard to patch, and what happens when AI-assisted research uncovers an N-day vulnerability? Tod Beardsley breaks down the rediscovery of CVE-2024-38508 (root privilege escalation in Lenovo XCC2 firmware) from runZero’s LightsOut project presented at Black Hat and DEF CON. Key insights: ✅️ BMC patching and downtime challenges ✅️ Technical breakdown of the bug ✅️ Finding affected devices