Supermicro X10 and X11 servers with authentication bypass vulnerability exposed to the internet. Supermicro has released BMC updates for the affected products to address the vulnerabilities. The vulnerability affects 47,339 Supermicro BMCs from over 90 different countries with this service exposed directly to the Internet. The vulnerabilities are not the first to be found in BMCs, so companies should isolate these management interfaces so they can be isolated from the internet, Eclypsium researchers said in their report. The researchers created a proof-of-concept using Facedancer, an open-source framework that allows emulating USB devices.”]

