CVE Tools

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

SecurityWeekBy Ionut Arghire

PoC publicBaseboard Management Controller (BMC)

Our summary

A long-standing vulnerability in Baseboard Management Controllers (BMC) has been found to leave thousands of data centers vulnerable to attacks. The flaw, identified as CVE-2013-4786, was first introduced in 2004 and affects the IPMI 2.0 authentication protocol. Cybersecurity firm Lava reported that nearly 37,000 server-management interfaces on the internet are currently exposed, with over 24,000 leaking password-derived hashes during the authentication process. This weakness allows attackers to extract and crack passwords offline using GPU tools, enabling unauthorized access to highly privileged control systems.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store