Security researchers have revealed a security vulnerability in the Lighttpd web server used in baseboard management controllers used by multiple vendors.
Lighttpd itself was patched in Aug 2018, but remains unpatched in AMI MegaRAC BMC. Intel and Lenovo have opted to not patch the vulnerability as the products incorporating them are end-of-life.
Affected users are advised to upgrade to a supported product.
https://thehackernews.com/2024/04/intel-and-lenovo-bmcs-contain-unpatched.html