|
|
|
|
|
by zamadatix
2889 days ago
|
|
Yes, it's what the CVEs are about, but the whole comment thread has been riddled with people talking past one another creating confusion: - The CVEs are about AMT portion only not the base IME - Not all affected hardware will be patched (based on age) - AMT can be disabled (and is by default) - IME/AMT run on a croprocessor on the motherboard - not the CPU itself - AMT runs an HTTP server for IPMI abilities |
|
IPMI doesn't use HTTP.
AMT/vPro is apparently not for servers, and likely operates on the system NIC. The first rule of out-of-band management interfaces should be "use a physically-separate interface", which is unfortunately frequently broken (by one vendor when the procurement specified a separate interface).