Connect with us

Security

Unsecured Internet-Exposed BMCs Leaking IPMI Password Hashes: A Security Breach Investigation

Published

on

Cybersecurity Alert: 36,000 BMC Management Interfaces Exposed to the Internet

Security researchers have raised concerns about more than 36,000 Baseboard Management Controller (BMC) management interfaces that are exposing the Intelligent Platform Management Interface (IPMI) protocol to the public internet.

A recent report from Lava revealed that out of these internet-exposed interfaces, 24,650 are disclosing password-derived authentication hashes due to a vulnerability in the IPMI v2.0 specification. This flaw, identified as CVE-2013-4786, allows remote attackers to obtain password hashes for valid accounts and conduct offline password guessing attacks.

According to Dell, this vulnerability is inherent to the IPMI v2.0 specification, and there is currently no patch available to address it.

Specialized BMCs are essential components embedded on a server’s motherboard, managing various functions such as power control, firmware updates, and remote console access. However, their exposure to the internet poses a significant security risk, especially with the potential for offline password cracking and unauthorized access.

As highlighted by Eclypsium, BMCs can be attractive targets for cyber attackers seeking remote control over systems and the deployment of malicious software.

The research emphasizes the critical nature of addressing vulnerabilities like CVE-2013-4786 to mitigate the risks associated with exposed BMC interfaces. Measures such as blocking UDP port 623, rotating passwords, and restricting BMC access to private networks are recommended to enhance security.

It is crucial for organizations to prioritize securing BMCs, as these management controllers play a vital role in maintaining the integrity and security of data centers and server infrastructure.

BMC Vulnerability

The findings underscore the importance of proactive security measures to safeguard against potential threats targeting BMC interfaces. By implementing best practices and staying vigilant, organizations can enhance their overall cybersecurity posture and protect critical infrastructure from malicious actors.

See also  Microsoft Bolsters Windows Security with Enhanced Remote Desktop File Protections

Trending