HomeMalware & Threats24,650 Internet-Exposed BMCs Reveal IPMI Password Hashes Pre-Login

24,650 Internet-Exposed BMCs Reveal IPMI Password Hashes Pre-Login

Published on

spot_img

Cybersecurity Alert: Exposed BMC Interfaces Present Significant Risks to Organizations

Cybersecurity researchers have raised a significant alarm after discovering over 36,000 Baseboard Management Controller (BMC) management interfaces that are exposing the Intelligent Platform Management Interface (IPMI) protocol to the public internet. These findings highlight a substantial vulnerability that poses risks not just to individual organizations but potentially to entire cloud infrastructures.

The alarming statistic of 36,872 internet-exposed server-management interfaces running IPMI reveals a troubling reality: 24,650 of these interfaces were found to leak password-derived authentication hashes before the login phase. This disclosure stems from a critical flaw in the IPMI v2.0 specification, first introduced in February 2024. According to a report by Lava, which was shared with The Hacker News, this vulnerability allows malicious individuals to exploit these weaknesses in various server environments.

The identified issue, classified as CVE-2013-4786, has a high-severity rating of 7.5 on the Common Vulnerability Scoring System (CVSS). This flaw enables remote attackers to retrieve password hashes associated with valid user accounts. Consequently, attackers can carry out offline password guessing attacks by collecting the HMAC from messages exchanged during the RMCP+ Authenticated Key-Exchange Protocol (RAKP) process within vulnerable BMCs.

Dell, in an advisory regarding the problem, has clarified that this vulnerability is an inherent flaw within the IPMI v2.0 specification, emphasizing that no patch is currently available to mitigate the risks. Security researcher Michael Katchinskiy reported that over 30% of the returned hashes corresponded to passwords that could be easily recovered using common wordlists and predictable factory chassis-sticker formats. Moreover, the exposure affected modern Supermicro and HPE servers, even within GPU providers’ networks, where some systems were still utilizing factory-issued passwords.

BMCs serve critical functions in managing server hardware. These specialized management processors, located on a server’s motherboard, oversee tasks such as power management, firmware control, remote console access, operating system installation, and system recovery. They play a crucial role in automating data center operations and improving system uptime by overseeing hardware telemetry and facilitating the mass deployment of firmware updates and BIOS configurations. Typically, BMCs communicate with hardware through protocols like IPMI and Redfish.

Eclypsium, a firmware security company, has previously highlighted the vulnerabilities in BMC supply chains. They point out that the privileged position of BMCs renders them ideal targets for malicious actors aiming to gain remote control and install persistent malware. Owing to their independent operation from the host operating system—referred to as Out-of-Band (OOB) management—an attacker who successfully compromises an exposed BMC can circumvent traditional security measures, maintain access, and operate undetected.

In modern AI data centers, where multiple tenants often share the same bare-metal environment, the implications of an exposed BMC grow significantly. A single compromised BMC can jeopardize numerous organizations’ workloads through shared infrastructure, presenting a substantial blind spot in the framework supporting the growing AI data center ecosystem.

The core of this concern is anchored in the 20-year-old vulnerability CVE-2013-4786. Researchers explain that, during the authentication phase, the BMC can return a response message containing an HMAC-SHA1 authentication code derived from the account password and session values known to the requester. An unauthenticated remote party with access to UDP port 623 can request this response, enabling them to conduct offline tests of password guesses. Unlike traditional online login attempts, the offline testing does not necessitate a new request for each password candidate.

As of May 6, 2026, an analysis of the public internet data concerning IPMI services unveiled 36,872 unique hosts with over 14,000 of them situated in the United States. The geographical distribution of the remaining vulnerable systems predominantly spans Germany, China, the Netherlands, and the U.K.

Further scrutiny has revealed that nearly 25,000 exposed BMCs inadvertently facilitated offline credential cracking by revealing password-derived authentication materials before login. Disturbingly, 6,240 BMCs provided authentication data for an empty username that matched weak password candidates, while 2,340 BMCs returned authentication information for standard accounts like “ADMIN” or “root” with passwords easily derived from publicly accessible lists.

In practical tests conducted by Lava, the factory passwords for HPE iLO systems proved recoverable in under a minute when utilizing modern GPU hardware. Similarly, Supermicro factory passwords were recoverable in about one hour, despite being assigned uniquely to each server. In response to these troubling findings, Supermicro has indicated plans to evaluate possible enhancements to its default password policy in future hardware versions.

Despite the non-novelty of CVE-2013-4786, its threat landscape has evolved. The emergence of GPU-based cracking has significantly accelerated the offline password recovery process, while the expansive deployment of AI engines has increased the stakes for each exposed server.

Compounding the situation, there are indications that malicious actors are currently targeting these internet-exposed BMC interfaces. Notably, ransomware operators have reportedly left extortion notes on HPE iLO 4 login pages. The identities of these actors remain unclear; however, there were indications as far back as 2020 of iLO servers being leveraged for nefarious purposes, including deploying the iLOBleed rootkit.

To mitigate the associated risks, industry experts recommend that organizations block UDP port 623 at their network boundaries. Additionally, organizations are urged to rotate factory-issued passwords during initial provisioning, disable outdated or vulnerable protocols like IPMI 1.5, limit BMC access to dedicated private management networks, and implement strict access controls to ensure that only authorized administrative systems can interact with BMC interfaces.

Acknowledging the existing vulnerabilities and the lessons learned is crucial, as Yakir Kadkoda, CTO and co-founder at Lava, points out. He stressed that while organizations have devoted considerable efforts to strengthening cloud workloads and operating systems, many have neglected to secure the infrastructure that underpins these systems. The inherent powers of these management controllers grant attackers immense control over servers and data centers. Moreover, once compromised, intruders can navigate beneath the radar of numerous security tools, retain persistence post-system rebuilds, and potentially penetrate deeper into critical infrastructure. As the demand for AI infrastructure continues to surge, securing this layer of the IT ecosystem has become an urgent priority.

Source link

Latest articles

A 13-Year-Old Vulnerability Exposes Tens of Thousands of Data Center Management Systems

The Dangers of a Disturbing Attack Method in Cloud Infrastructure In the ever-evolving landscape of...

US FCC Prohibits Sale of Foreign-Made Power Inverters and Robots

Interagency Review Raises Concerns About Internet-Connected Inverters and Potential Grid Vulnerabilities In a significant move...

Cybercriminals Leverage Adversarial Prompt Injection to Bypass AI-Powered Security Tools

Rise of Adversarial Prompt Injection: A New Threat to AI Security In an alarming development...

Microsoft Unveils Multiple AI Security Initiatives

Microsoft Unveils Advanced AI-Driven Security Initiatives On July 27, at a notable Microsoft Security launch...

More like this

A 13-Year-Old Vulnerability Exposes Tens of Thousands of Data Center Management Systems

The Dangers of a Disturbing Attack Method in Cloud Infrastructure In the ever-evolving landscape of...

US FCC Prohibits Sale of Foreign-Made Power Inverters and Robots

Interagency Review Raises Concerns About Internet-Connected Inverters and Potential Grid Vulnerabilities In a significant move...

Cybercriminals Leverage Adversarial Prompt Injection to Bypass AI-Powered Security Tools

Rise of Adversarial Prompt Injection: A New Threat to AI Security In an alarming development...