Hasty Briefsbeta

Bilingual

24,650 internet-accessible BMCs leak password-derived hashes before login

a day ago
  • A 20-year-old vulnerability (CVE-2013-4786) in IPMI 2.0 allows offline password cracking by exposing password-derived hashes before authentication.
  • Over 36,000 data center servers exposed IPMI interfaces to the public internet, with 24,650 vulnerable to hash disclosure.
  • Weak or factory-default passwords on BMCs (e.g., Supermicro and HPE) are recoverable via GPU-based cracking within minutes to hours.
  • Compromised BMCs provide privileged, persistent access below the operating system, enabling lateral movement across management networks.
  • AI infrastructure is especially at risk due to shared management networks and high-value GPU systems.
  • Recommendations include blocking UDP port 623, replacing default passwords, isolating BMCs on private networks, and continuous monitoring.