Connect with us


Intel warning: Critical flaw in BMC firmware affects a ton of server products



Intel to Windows 10 users: You have patches for 19 severe flaws, use them!
Update Intel Windows graphics drivers, and stop using Intel Matrix Storage Manager and USB 3.0 Creator Utility.

Chip giant Intel has issued an alert over 13 security bugs in its version of the baseboard management controller (BMC) firmware for Intel Server products, including one critical flaw that could leak information or allow an attacker to escalate privileges. 

BMC firmware has been in the spotlight this year, due to several flaws that allow attackers to hijack cloud servers, as well as for vulnerabilities in big-brand server products that are difficult to patch. 

BMCs, which are used by multiple hardware makers, are part of a subsystem that enables admins to manage and monitor systems outside the view of the host system’s CPU, firmware, and operating system. 

SEE: Digital transformation: A CXO’s guide (ZDNet special report) | Download the report as a PDF (TechRepublic)

Intel was the main proponent of the computer interface for this subsystem, known as the intelligent Platform Management Interface (IPMI), which allows admins to do things to a system remotely underneath the operating system and firmware layer.

In other words, BMCs are part of a powerful set of capabilities. However, hardware makers aren’t always careful about how they’re secured – and these are the types of bugs that military hackers would probably look for. 

New attacks on firmware, which have higher privileges than the Windows kernel, was one reason Microsoft is launching new ‘Secured-core’ PCs. 

This effort drew on lessons it learned from hackers trying to bypass digital-rights management (DRM) technologies it uses to protect Xbox content. Otherwise, attacks on BMC firmware are largely invisible to antivirus technologies such as Microsoft Defender.  

Intel doesn’t offer much detail about the BMC firmware flaws affecting its server products, however it describes the critical flaw as a ‘Heap corruption’ bug in the Intel BMC firmware that “may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access”. It has a severity rating of 9 out of a possible 10.     

Collectively, the 13 flaws affect a dizzying array of models from Intel’s Server Board, Compute Module, and Server System line of products. Dozens of models from each product line are affected.   

Intel Server Boards that are affected, including model numbers BBS2600BPB, BBS2600BPQ, BBS2600BPS, BBS2600BPBR, BBS2600BPQR, BBS2600BPSR, S2600WF0, S2600WFQ, S2600WFT, S2600WF0R, S2600WFQR, S2600WFTR, S2600STB, S2600STQ, S2600STBR, S2600STQR, BBS2600STB, BBS2600STQ, BBS2600STBR, and BBS2600STQR.  

Intel Compute Modules that are affected include model numbers HNS2600BPB, HNS2600BPQ, HNS2600BPS, HNS2600BPB24, HNS2600BPQ24, HNS2600BPS24, HNS2600BPBLC, HNS2600BPBLC24, HNS2600BPBR, HNS2600BPBRX, HPCHNS2600BPBR, HNS2600BPQR, HPCHNS2600BPQR, HNS2600BPSR, HPCHNS2600BPSR, HNS2600BPB24R, HNS2600BPB24RX, HNS2600BPQ24R, HNS2600BPS24R, HNS2600BPBLCR, HNS2600BPBLC24R, S9256WK1HLC, S9248WK1HLC, S9232WK1HLC, S9248WK2HLC, S9232WK2HLC, S9248WK2HAC, and S9232WK2HAC. 


SEE: Intel unveils next-gen Movidius VPU, codenamed Keem Bay

Intel says the flaws “were found internally by Intel”, but it thanks Daniel Medina Velazquez for finding the critical flaw that is tracked as CVE-2019-11171.

To address the issue, Intel recommends users of its BMC firmware update to version 2.18 or later.

Source link

Continue Reading


2022 Land Rover Defender V8 brings 518hp to SUV icon



Land Rover has revealed its new 2022 Defender V8, adding a much-requested engine upgrade for the SUV, along with new special editions. Returning to the US for the first time in decades last year, the new Defender combines retro-inspired styling with the sort of off-road abilities you’d expect from what’s arguably the automaker’s most enduring nameplate.

While initial reviews – ours included – were generally positive, one omission was under the hood. Land Rover launched the Defender with a pair of inline-six engines as the biggest on offer, not exactly slow but also not having that V8 grunt that some fans of the SUVs really wanted. Happily, it’s being corrected for the new 2022 model year.

2022 Land Rover Defender 90 V8 and 110 V8

The 2022 Defender V8 will have a 5.0-liter supercharged V8, with 518 horsepower and 461 lb-ft of torque. It’ll be offered in both the Defender 110 and Defender 90 body styles – with five and three doors, respectively – with the latter doing 0-60 mph in 4.9 seconds and on to a top speed of 149 mph. That’ll make it the fastest and most powerful production Defender ever, Land Rover says.

As you’d expect, all-wheel drive is standard, along with special suspension and transmission tuning. There’s a new Electronic Active Rear Differential which the automaker says should deliver improvements in handling and body control, and an eight-speed automatic transmission. A new Dynamic program in the Terrain Response system will be exclusive to the V8 SUVs, intended for more spirited driving on asphalt and loose surfaces.

Helping there, there’ll be larger solid anti-roll bars, and retuned Continuously Variable Damping. Torque vectoring with braking is supported, with Land Rover fitting Xenon Blue front brake calipers for the 15-inch front discs. V8-exclusive 22-inch alloy wheels and quad tailpipes will also be offered, and there’ll be three colors – Carpathian Grey and Yulong White, both with a contrast Narvik Black roof, and Santorini Black – with Shadow Atlas exterior trim detailing.

Inside, there’ll be special Ebony Windsor Leather with Mike Suedecloth and Robustec accents. The exposed cross-car beam running along the dashboard will be finished in Satin Black. The steering wheel gets Alcantara on the rim and satin chrome paddle-shifters, along with leather on the airbag housing that matches the gear selector trim. Finally, the illuminated tread plates have V8 badging.

Pricing for the 2022 Defender V8 will be confirmed closer to the SUV’s arrival in US dealerships. That’ll happen later in the year.

2022 Defender V8 Carpathian Edition

Marking the arrival of the V8 option is the 2022 Defender V8 Carpathian Edition. It’ll be the flagship of the line-up, in exclusive Carpathian Grey premium metallic paint with a Narvik Black contrast roof, hood, and tailgate. Satin Black tow eyes, Carpathian Gloss front and rear skid pans and front grille bar, and Xenon Blue brake calipers will also set it apart.

Land Rover Satin Protective Film will give the exterior a semi-matte finish but also help protect from scrapes. Inside, it’ll be the same as the regular V8 SUV. Pricing will be confirmed closer to launch.

2022 Defender XS Edition

Replacing the Defender First Edition, the 2022 Defender XS Edition will also be offered in 110 and 90 body styles. It has body-colored lower cladding and lower wheel arches, with 20-inch, contrast diamond-turned alloy wheels finished in Satin Grey. Land Rover will offer it in four colors: Silicon Silver, Hakuba Silver, Gondwana Stone, and Santorini Black. Pricing will be confirmed closer to launch.

Inside, there are 12-way, heated and cooled electric memory seats in Ebony Grained leather and Robust Woven Textile. The Cross Car Beam has a Light Grey powder coat brushed finish, and Land Rover has added the extended leather package with illuminated metal treadplates.

For other specs, there’s the P400 mild-hybrid engine with 395 hp and 406 lb-ft of torque, electronic air suspension, adaptive dynamics, tri-zone climate control, and adaptive cruise control. It also features the updated Pivi Pro infotainment system, which is new for the 2022 model year. That has wireless device charging with a phone signal booster, plus can be had with a larger 11.4-inch touchscreen with curved glass.

Land Rover has simplified the menu structure, and there’s new navigation with dynamic guidance. Intelligent route learning promises to figure out your common routes and propose them – complete with adjustments for traffic – when you get into the car.

Still to come, more Land Rover Defender electrification

What Land Rover isn’t telling us, yet, is when the Defender will get its more serious electrification. The automaker has promised six pure electric variants across its range within the next five years, with a pure electric version of the Defender by the end of the decade.

Continue Reading


Fisker and Foxconn team on new EV with outsized ambitions



Fisker and Foxconn are teaming up on an an electric vehicle, with the EV-company and the manufacturing heavyweight aiming for go far beyond the niche production in the automaker’s past. Codenamed Project PEAR – or “Personal Electric Automotive Revolution” – the goal is to make a more affordable EV that can hit the sort of sales numbers more commonplace among mainstream gas models.

Fisker is probably best known for its role in the style-forward Karma hybrid sedan, a project now being run independently by Karma Automotive. Plans rebooted, Fisker first unveiled the EMotion EV back in 2018, a striking luxury electric sedan with double-gullwing doors.

Production for that, though, was put on the back-burner, as Fisker turned instead to more affordable, mainstream fare. The Fisker Ocean is promised to be a sub-$40k electric SUV, with the car company inking a deal with auto parts behemoth Magna to build the plug-in. Manufacturing is expected to begin in Q4 2022, and even without a production-ready prototype shown – something Fisker says will happen later this year – there are apparently upwards of 12k paid reservations for the car.

One vehicle does not an automaker make, though, and so Fisker is looking to its next model. That’ll be jointly developed by it and Foxconn, sold under the Fisker brand, and included as part of Fisker’s Flexee Lease program. Foxconn will be responsible for manufacturing, bringing the same heft that powers iPhone production to automotive.

Project PEAR – details on which are scant, currently – will be “destined for multiple global markets” Fisker said today. Production is currently earmarked for Q4 2023, and it’ll be the second EV in Fisker’s range.

Fisker’s ambitions aren’t exactly low. The expectation is that it’ll take just 24 months to develop the car, including research and development, and becoming production-ready. That’s about half the time most automakers would expect to take. Foxconn hasn’t been shy about its EV hopes in the past, either, already cutting deals with Byton and Fiat Chrysler in the past on electric vehicle technology.

“The key success elements of electric vehicle development include the electric motor, electric control module and battery,” Young-way Liu, Foxconn Technology Group Chairman, said today in a statement. “We have two major advantages in this regard, with an exceptional vertically integrated global supply chain and the best supply chain management team in our industry.”

Discussions are underway between the firms, with a formal partnership expected to be signed in Q2 2021. The two firms are aiming high, too, with projected 250,000 annual volume of the vehicle. Exactly what it will look like, cost, how much range it might pack, where it will launch, and other details are still in short supply: Fisker’s design inspiration sketch would seem to imply a crossover of some sort, a sensible choice given the skew of sales right now toward that category.

Continue Reading


2021 Mitsubishi Outlander PHEV has more range, more power, and a lower base price



That’s right. Mitsubishi will continue selling the 2021 Outlander PHEV alongside the all-new, Rogue-based 2022 Outlander. The Japanese carmaker is burning the midnight oil in conceptualizing a new plug-in hybrid (PHEV) based on the new model, but Mitsubishi is not leaving anything to chance.

The carmaker is making sure it has a crossover PHEV in its lineup for customers, and is the reason why you’ll find the 2021 Outlander PHEV together with the new 2022 Outlander in Mitsubishi showrooms.

Nevertheless, Mitsubishi’s making sure you get the most bang for your buck in the 2021 Outlander PHEV. It starts with a more robust and fuel-efficient 2.4-liter four-cylinder gas engine producing 126 horsepower and 148 pound-feet of torque. Next, the previous 60 kW rear-mounted electric motor makes way for a more potent 70 kW unit.

As expected, the power figures are quite generous for a midsize crossover. The 2021 Mitsubishi Outlander PHEV’s advanced hybrid powertrain pumps out 221 horsepower, 31 more horses than the outgoing model. It also has a more significant 13.8 kWh battery pack (the old model had a 12.0 kWh battery), boosting the all-electric range from 22 to 24 miles.

Admittedly, the 2-miles range boost is small by modern EV standards. But for most people, it’s enough to cover a trip to a grocery or convenience store without burning a drop of fuel. And since the new Outlander PHEV has a better range, it now qualifies for larger tax incentives depending on where you live.

Sold in three trim models, the base 2021 Outlander PHEV SEL-AWC starts at $37,490 (including $1,195 destination fees). It now qualifies for up to $6,587 in federal incentives, increasing around $750 over the old model, further lowering the MSRP.

Meanwhile, the Outlander PHEV LE S-AWC has base prices starting at $39,190, while the range-topping GT S-AWC model starts at $43,190 before federal and state credits. The former adds a blacked-out grille, a sunroof, bespoke 18-inch alloy wheels, and blacked-out bumpers. The good news? Mitsubishi’s Outlander PHEV is available to order now.

Continue Reading