Over 24,000 Server BMCs Exposed Online, Leaking Password Hashes via 2013 Flaw
A recent internet scan discovered 24,650 server Baseboard Management Controllers (BMCs) publicly exposed and vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 protocol dating back to 2013. Attackers can initiate an unauthenticated authentication handshake over UDP port 623 to obtain a password-derived hash, which can then be cracked offline using GPUs without triggering any alerts on the target system. Of the exposed devices, 2,340 were found using weak or default administrator passwords, making them especially easy to compromise. Successful exploitation grants attackers deep, below-OS control over affected servers, including power management, firmware updates, and virtual media — capabilities that persist even after an OS reinstall. Security experts recommend isolating BMC interfaces from the internet, enforcing strong unique passwords, disabling unnecessary IPMI services, and forwarding BMC logs to external monitoring systems.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in