
Cloudflare’s approach to handling BMC vulnerabilities
5/26/2022
This post details Cloudflare's response to critical vulnerabilities discovered in BMC software used in their fleet. It outlines the background of BMCs, the specific vulnerabilities (Pantsdown, USBAnywhere, and others related to AST2400/AST2500 chips), and the mitigation strategies employed, including firmware updates, network segmentation, reduced exposure of BMC interfaces, strict password policies, and comprehensive logging. The post also announces Cloudflare's strategic shift towards OpenBMC for future BMC firmware and the extension of secure boot to the BMC itself.