Exposed BMCs hand out password hashes before login
ResearchIPMI 2.0BMCOur summary
A vulnerability in IPMI 2.0 allows attackers to retrieve password hashes from a server's BMC without authenticating, simply by sending a request to UDP port 623. This flaw, identified as CVE-2013-4786, affects BMCs from vendors like Supermicro and HPE. Researchers found that nearly two-thirds of exposed BMCs leaked authentication material, enabling offline brute-force attacks. Default factory passwords used on many devices are also vulnerable to rapid cracking using modern GPU setups. Lava researchers recommend blocking UDP port 623 at the network perimeter and replacing default credentials to mitigate risk.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.