CVE Tools

Flaw From 2002 Exposes Data Centers to Server Takeover

Dark ReadingBy Jai Vijayan

Reported exploitedIPMI 2.0BMC

Our summary

A critical vulnerability dating back over two decades has been actively exploited to compromise thousands of exposed server management controllers, putting data centers at risk of full server takeover. The flaw, tracked as CVE-2013-4786, resides in the IPMI 2.0 authentication protocol and allows unauthenticated attackers to extract password hashes from BMCs via UDP port 623. Researchers from Lava discovered that 24,650 BMC endpoints are vulnerable, with many using weak or default credentials that can be brute-forced quickly. Attackers have already leveraged this issue in real-world campaigns targeting major industries, including ransomware attacks against large automotive component manufacturers. Vendors involved include Supermicro and others using BMC and Redfish interfaces. Immediate mitigation includes isolating BMCs from public networks and replacing weak credentials.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store