Security Researcher Warns on Sipeed's NanoKVM "It's as Bad as IoT [Stuff] Comes"
A security researcher discovered serious vulnerabilities in Sipeed's NanoKVM firmware, prompting plans for a more secure version by mid-August 2024 and a port of PiKVM software to improve security.
Read original articleA security researcher known as "lichtlos" has identified multiple vulnerabilities in the firmware of Sipeed's NanoKVM, a network-connected keyboard, video, and mouse control device. The researcher described the firmware as having serious security flaws, including hard-coded secrets, a lack of input validation, and configurations that grant root privileges to all operations. Sipeed's Caesar Wu acknowledged these issues, attributing them to a rapid development process and confirming that a more secure firmware version is expected to be released by mid-August 2024. The NanoKVM, which was launched in beta form, allows users to control devices remotely via a web interface but is currently not recommended for production use due to its security shortcomings. Plans are underway to port the PiKVM software, which is designed for Raspberry Pi, to the NanoKVM to address these vulnerabilities, although no specific timeline has been provided. The firmware is currently closed source, but users can access its components for analysis.
- Security researcher "lichtlos" found serious vulnerabilities in Sipeed's NanoKVM firmware.
- Issues include hard-coded secrets, lack of input validation, and root privilege configurations.
- Sipeed plans to release a more secure firmware version by mid-August 2024.
- The NanoKVM is not recommended for production use until security issues are resolved.
- A port of the PiKVM software is planned to enhance security features.
Related
Vulnerability in Popular PC and Server Firmware
Eclypsium found a critical vulnerability (CVE-2024-0762) in Intel Core processors' Phoenix SecureCore UEFI firmware, potentially enabling privilege escalation and persistent attacks. Lenovo issued BIOS updates, emphasizing the significance of supply chain security.
Sipeed/NanoKVM: NanoKVM: Affordable, Multifunctional, Nano RISC-V IP-KVM
The GitHub URL offers details on NanoKVM, an IP-KVM product on LicheeRV Nano. It covers product info, specs, hardware platform, and community links. For further details, feel free to inquire.
Secure Boot is completely broken on 200 models from 5 big device makers
Researchers from Binarly found that Secure Boot is compromised on over 200 device models due to a leaked cryptographic key, posing significant security risks until manufacturers issue firmware updates.
Compromising the Secure Boot Process
Researchers from Binarly revealed a security vulnerability in the Secure Boot process affecting over 200 device models due to a leaked cryptographic key, raising concerns about potential cyberattacks and security practices.
Secure Boot useless on PCs from major vendors after key leak
A study by Binarily found that hundreds of PCs from major manufacturers are vulnerable due to a leaked 12-year-old test platform key, allowing attackers to bypass Secure Boot protections.
Related
Vulnerability in Popular PC and Server Firmware
Eclypsium found a critical vulnerability (CVE-2024-0762) in Intel Core processors' Phoenix SecureCore UEFI firmware, potentially enabling privilege escalation and persistent attacks. Lenovo issued BIOS updates, emphasizing the significance of supply chain security.
Sipeed/NanoKVM: NanoKVM: Affordable, Multifunctional, Nano RISC-V IP-KVM
The GitHub URL offers details on NanoKVM, an IP-KVM product on LicheeRV Nano. It covers product info, specs, hardware platform, and community links. For further details, feel free to inquire.
Secure Boot is completely broken on 200 models from 5 big device makers
Researchers from Binarly found that Secure Boot is compromised on over 200 device models due to a leaked cryptographic key, posing significant security risks until manufacturers issue firmware updates.
Compromising the Secure Boot Process
Researchers from Binarly revealed a security vulnerability in the Secure Boot process affecting over 200 device models due to a leaked cryptographic key, raising concerns about potential cyberattacks and security practices.
Secure Boot useless on PCs from major vendors after key leak
A study by Binarily found that hundreds of PCs from major manufacturers are vulnerable due to a leaked 12-year-old test platform key, allowing attackers to bypass Secure Boot protections.