Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Summary
A decades-old vulnerability in Baseboard Management Controllers (BMCs) is exposing thousands of data centers to attacks. Over 24,000 internet-accessible BMC interfaces are disclosing authentication hashes before a user logs in, making them vulnerable to brute-force attacks.
IFF Assessment
This vulnerability allows attackers to obtain authentication hashes, which can then be used to gain unauthorized access to sensitive data center systems.
Severity
The vulnerability allows for unauthorized access to sensitive information (authentication hashes) and can lead to further compromise of critical infrastructure, indicating a high impact. The attack vector is network-based and relatively easy to exploit given the widespread exposure and disclosure of hashes, suggesting high exploitability.
Defender Context
This highlights the critical need for defenders to audit and secure their BMC interfaces, ensuring they are not exposed to the internet and that authentication mechanisms are robust. Organizations should prioritize patching or mitigating this long-standing vulnerability to prevent unauthorized access to their data center infrastructure.