Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
PoC publicBaseboard Management Controller (BMC)Our summary
A long-standing vulnerability in Baseboard Management Controllers (BMC) has been found to leave thousands of data centers vulnerable to attacks. The flaw, identified as CVE-2013-4786, was first introduced in 2004 and affects the IPMI 2.0 authentication protocol. Cybersecurity firm Lava reported that nearly 37,000 server-management interfaces on the internet are currently exposed, with over 24,000 leaking password-derived hashes during the authentication process. This weakness allows attackers to extract and crack passwords offline using GPU tools, enabling unauthorized access to highly privileged control systems.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.