22-Year-Old IPMI Vulnerability Exposes 24,000 Servers to Offline Password Attacks

www.news4hackers.com-22-year-old-ipmi-vulnerability-exposes-24-000-servers-to-offline-password-attacks-22-year-old-ipmi-vulnerability-exposes-24-000-servers-to-offline-password-attacks

Security Researchers identified a critical vulnerability in the Intelligent Platform Management Interface (IPMI) protocol, exposing over 24,000 servers to potential unauthorized access through compromised password authentication mechanisms.

Critical Vulnerability in IPMI Protocol

The flaw, tied to CVE-2013-4786, allows attackers to extract cryptographic responses derived from administrator credentials without requiring successful authentication. This discovery highlights the risks of outdated management protocols and weak default configurations in enterprise infrastructure.

Analysis of BMC Interfaces

A comprehensive analysis of 36,872 publicly accessible Baseboard Management Controller (BMC) interfaces revealed that 24,650 of them transmitted password-derived authentication data during unauthenticated IPMI 2.0 protocol interactions. BMCs, which function as embedded management systems within server hardware, enable remote control capabilities such as power cycling, firmware updates, and hardware diagnostics.

Origin of the Vulnerability

When exploited, these interfaces can grant attackers control over physical servers independent of the operating system, bypassing traditional endpoint security measures. The vulnerability stems from the IPMI 2.0 authentication process, which was introduced in 2004 and later assigned a CVE identifier in 2013.

Weak and Default Credentials

During an authentication attempt, vulnerable BMCs generate a cryptographic response based on the stored password. While this response does not expose the password itself, it enables offline brute-force attacks by allowing adversaries to test potential credentials without triggering server-side alerts. Weak and default credentials significantly exacerbated the risk.

Factory-Set Credentials Vulnerabilities

Researchers discovered 6,240 systems that accepted empty usernames and produced authentication data linked to weak passwords. Additionally, 2,340 devices used predefined accounts such as ADMIN or root, with passwords matching entries in public password databases. Factory-set credentials also proved vulnerable, even when unique passwords were assigned.

For example, certain Supermicro servers utilized 10-character uppercase sequences printed on chassis labels, while HPE iLO systems employed 8-character alphanumeric combinations. These predictable formats drastically reduced the complexity of cracking attempts.

Testing and Results

In controlled testing, researchers recovered factory-configured passwords for two modern Supermicro servers operated by a GPU provider. Although no unauthorized access was achieved, the exposure was promptly addressed after notification. Similar tests on an HPE server in a laboratory environment confirmed that over 30% of captured hashes could be decrypted using common wordlists or factory password patterns.

Security experts emphasized the challenges of mitigating this issue due to the inherent design of IPMI. Unlike software vulnerabilities, CVE-2013-4786 is embedded in the protocol itself, requiring network-level restrictions rather than patch-based solutions.

Conclusion

The research underscores the persistent risks of legacy protocols in modern infrastructure. Organizations are urged to reassess BMC configurations, prioritize secure authentication practices, and implement network segmentation to prevent unauthorized access to critical management interfaces.



About Author

en_USEnglish