BMC research finds 24,650 servers leaking password hashes

Research finds tens of thousands of internet-facing BMCs disclosing IPMI password hashes without authentication.

CSBadmin
1 Min Read

Researchers have found tens of thousands of internet-exposed server management interfaces that disclose password-derived hashes before any login. A scan by Lava identified 36,872 Baseboard Management Controller interfaces running the Intelligent Platform Management Interface protocol, and 24,650 of them leak authentication hashes without credentials.

The exposure traces to a flaw published 13 years ago (CVE-2013-4786) in IPMI 2.0 that allows retrieval of password hashes without authentication. Lava’s red team was able to compromise BMCs within minutes by guessing basic passwords.

BMCs provide out-of-band remote control over servers without physical access, letting administrators manage hardware even when the operating system is down. The researchers describe the layer beneath the OS as a no man’s land that is becoming an attacker target, since a compromised BMC can offer a foothold into the wider data center environment.

Defenders should restrict IPMI and BMC management interfaces to dedicated management networks, disable the protocol where it is not needed, change default credentials, and monitor out-of-band channels for suspicious activity.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.