Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Summary
Over 24,000 internet-exposed servers are leaking authentication password hashes because of a two-decade-old vulnerability in their Baseboard Management Controller (BMC) interfaces. This flaw allows attackers to retrieve the password hash from unpatched servers, enabling them to gain administrative access and potentially compromise the entire system. The vulnerability, identified as CVE-2023-46203, affects various server vendors and has been known for years, yet many systems remain unpatched.
IFF Assessment
This vulnerability allows attackers to easily obtain password hashes, granting them unauthorized administrative access to servers and posing a significant risk to data confidentiality and system integrity.
Severity
The CVSS score of 9.1 reflects a critical severity. The vulnerability allows for network-based exploitation (AV:N) with low complexity (AC:L), requiring no privileges (PR:N) and no user interaction (UI:N). The impact on confidentiality, integrity, and availability is high (I:H, C:H, A:H), as it enables full administrative control over the BMC.
Defender Context
Defenders should prioritize patching or securing internet-facing BMC interfaces to mitigate the risk of unauthorized access and subsequent system compromise. This incident highlights the persistent danger of unaddressed legacy vulnerabilities in critical infrastructure components, emphasizing the need for regular asset inventory and vulnerability management.