A vulnerability that has persisted for 22 years in Baseboard Management Controller (BMC) management processors has put thousands of data centers at risk, according to a report by cybersecurity firm Lava. This flaw, identified as CVE-2013-4786, affects the widely used IPMI protocol and permits attackers to extract authentication hashes before login, exposing over 24,000 server-management interfaces globally to potential breaches. BMCs, which are integral to server platforms, allow administrators to perform critical management tasks such as firmware updates and hardware monitoring, often making them a target for attacks due to their high-level access.

The issue arises because these interfaces often share user databases, meaning a credential valid for one interface could potentially be used across others. This vulnerability is particularly concerning because it allows attackers to gather password hashes, which can then be cracked offline, bypassing the need for multiple login attempts that could trigger security alerts. The report highlights that many of these systems are susceptible due to using weak, reused, or default passwords, exacerbated by predictable factory-issued formats.

Lava's findings indicate that over 6,240 hosts were found to accept an empty username with a weak password, with another 2,340 hosts using named accounts like 'Admin' or 'root' with commonly found passwords. This vulnerability underscores a broader security issue within data center management infrastructure, as BMCs, despite their critical role, often lack adequate monitoring and protection. The combination of weak credential practices and the power of modern GPU-based cracking makes these BMCs an attractive target for attackers seeking a foothold in the management network.