A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.
#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity
https://securityonline.info/hpe-edgeconnect-authorization-bypass/?utm_source=mastodon&utm_medium=jetpack_social
#hpe
2 posts · Last used 21d
Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special.
That is, until I noticed what machine was listed. Introduced late 2015/early 2016
I have never purchased whatever support. Both Supermicro and Dell work this way.
HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you
In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer.
However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash
#Rant #Security #Vulnerabilities #Hardware #Servers #HPE #SysOp #Homelab
You've seen all posts