A significant vulnerability has been discovered in 24,000 Internet-exposed Baseboard Management Controllers (BMCs) that threatens the security of data centers worldwide. This long-standing flaw, linked to the IPMI 2.0 authentication protocol, allows attackers to gain unauthorized access by exploiting password-derived authentication hashes. Researchers at Lava first identified the flaw, which is nearly invisible to conventional security tools because BMCs operate independently of a server's operating system and kernel.
The issue is rooted in a vulnerability identified as CVE-2013-4786, which allows a BMC to return authentication hashes to an unauthenticated client, enabling offline password cracking. Attackers can exploit this flaw by accessing UDP port 623, potentially compromising weak, reused, or factory-set passwords. Lava's research found over 24,650 BMC endpoints susceptible to this vulnerability, with thousands accepting weak or predictable passwords and some even using default passwords not commonly found in wordlists.
Yakir Kadkoda, the CTO of Lava, highlights the grave risks posed by this vulnerability. BMCs are critical control points in data centers, offering extensive access to underlying hardware. If compromised, attackers can gain a foothold in the data center, potentially spreading to other servers and management systems. This could lead to severe consequences, including unauthorized remote control, firmware manipulation, or ransomware deployment.
Kadkoda urges organizations to remove BMC and IPMI interfaces from the public Internet as an immediate measure. However, he emphasizes that further actions are necessary, such as isolating BMCs on dedicated management networks, replacing weak credentials, and disabling insecure legacy features. Continuous monitoring of the out-of-band management network is also essential to detect and prevent unauthorized access.


