Back to News
Market Impact: 0.65

Attacks on remote maintenance weak points in servers from HPE, Lenovo and Co.

HPEFTNT
Cybersecurity & Data PrivacyTechnology & InnovationInfrastructure & Defense
Attacks on remote maintenance weak points in servers from HPE, Lenovo and Co.

CISA has issued a warning regarding active exploitation of critical security vulnerabilities, most notably a CVSS 10.0 flaw in AMI MegaRAC remote maintenance firmware affecting servers from major vendors like HPE and Lenovo. This "Redfish Authentication Bypass" allows unauthorized access to critical server infrastructure due to unapplied patches, alongside ongoing attacks on end-of-life D-Link routers and an old Fortinet FortiOS backdoor. The inclusion in CISA's "Known Exploited Vulnerabilities" catalog highlights a significant, widespread systemic risk to enterprise IT security, potentially leading to operational disruptions and data breaches for affected organizations.

Analysis

A recent CISA security alert highlights active exploitation of a critical vulnerability (CVSS 10.0) in AMI MegaRAC remote maintenance firmware, directly impacting servers from major vendors including Hewlett Packard Enterprise (HPE) and Lenovo. This "Redfish Authentication Bypass" flaw allows for a complete takeover of server baseboard management controllers, a risk amplified by the slow rollout and adoption of patches provided in mid-March. The situation points to a significant weakness in the hardware supply chain, where firmware updates from providers like AMI are not being effectively integrated by manufacturers and deployed by end-users. The issue is compounded by poor security practices, such as leaving default remote maintenance ports exposed to the internet. Furthermore, the alert flags ongoing attacks against end-of-life D-Link routers and a Fortinet (FTNT) FortiOS vulnerability known since 2019, underscoring a persistent risk from legacy and unpatched systems within enterprise environments. CISA's inclusion of these flaws in its "Known Exploited Vulnerabilities" catalog elevates the threat level, signaling significant potential for operational disruption and data breaches for organizations using this hardware, and reflects negatively on the security posture of the implicated vendors, as indicated by the strongly negative sentiment scores for both HPE (-0.8) and FTNT (-0.7).

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.75

Ticker Sentiment

FTNT-0.70
HPE-0.80

Key Decisions for Investors

  • Investors in Hewlett Packard Enterprise (HPE) should monitor for any disclosures regarding the financial or reputational impact from the critical CVSS 10.0 vulnerability in its server products.
  • The re-emergence of a 2019 vulnerability in Fortinet (FTNT) products, despite long-available patches, may signal underlying issues with customer patch adoption and long-term ecosystem security, representing a potential headwind.
  • This widespread hardware vulnerability may act as a catalyst for increased enterprise spending on cybersecurity services and infrastructure audits, potentially benefiting companies in the threat detection and security consulting sectors.
  • Consider scrutinizing portfolio companies for exposure to legacy and end-of-life hardware, as these incidents demonstrate a persistent and actively exploited source of enterprise risk.