24,000 Exposed BMCs Vulnerable to Password Hash Leak via Decades-Old Flaw

www.news4hackers.com-24-000-exposed-bmcs-vulnerable-to-password-hash-leak-via-decades-old-flaw-24-000-exposed-bmcs-vulnerable-to-password-hash-leak-via-decades-old-flaw

Over 24,000 internet-facing server management interfaces are leaking authentication credentials due to a critical flaw in BMC systems, posing significant security risks.

Overview of the Vulnerability

The vulnerability, tracked as CVE-2013-4786, stems from a 20-year-old weakness in the IPMI 2.0 protocol introduced in 2004. Researchers identified that more than 24,000 servers expose password hashes through this flaw, enabling attackers to perform offline password-cracking operations using specialized hardware.

Critical Flaw in BMC Systems

BMCs are embedded processors designed for remote server management, allowing administrators to execute low-level tasks such as power cycling, firmware updates, and virtual media mounting. These interfaces operate independently of the host operating system, making them a critical attack surface.

Impact and Scope

Compromise of a BMC could grant adversaries control over physical infrastructure, enabling them to alter configurations, deploy malicious firmware, and bypass traditional security monitoring tools. The study focused on IPMI services accessible over UDP port 623, identifying 36,872 internet-exposed hosts. Of these, 24,650 contained authentication material vulnerable to offline cracking.

Exposure Statistics

Researchers identified that 6,240 of the exposed systems accepted blank usernames during authentication, while 2,340 used passwords matching publicly available dictionaries. This indicates a significant risk of unauthorized access. Geographically, 39% of the vulnerable servers are located in the United States.

Technical Details

The research highlighted that many affected systems belong to Supermicro hardware, which employs 10-character uppercase passwords printed on chassis labels. Although this format theoretically offers sufficient complexity, its predictable structure allows rapid decryption using GPU-based cracking tools. For comparison, the team estimated that recovering an HPE factory password would require approximately one day per captured authentication response on an Apple M3 system.

Ransom Note Discovery

Researchers observed a ransom note demanding 0.3 BTC on an exposed HPE iLO 4 login page, suggesting potential malicious activity. However, this does not confirm widespread exploitation.

Mitigation Strategies

Supermicro acknowledged the risk and advised administrators to change default BMC passwords and isolate management networks. The company also stated it would evaluate stronger default password policies for future hardware. HPE responded with a standard automated message and did not provide further details.

Recommendations for Security Teams

The researchers emphasized that mitigating the risk requires keeping IPMI and Redfish interfaces off public networks, rotating factory credentials, restricting access to dedicated management segments, and disabling legacy authentication protocols. Security teams are urged to proactively audit BMC settings and implement layered defenses to prevent exploitation.

According to the research team, “The findings underscore the persistent dangers of outdated protocols and weak default configurations in critical infrastructure.”

Conclusion

The vulnerability highlights the urgent need for organizations to address outdated protocols and weak default configurations. Proactive measures, such as updating BMC passwords and isolating management networks, are critical to mitigating risks and protecting physical infrastructure from exploitation.


Blog Image

About Author

en_USEnglish