A critical security flaw affecting baseboard management controller (BMC) systems has left over 24,000 server management interfaces exposed to potential attacks. The vulnerability allows attackers to obtain authentication hashes before completing the login process, creating a serious security risk for data centers worldwide. Despite being decades old, the flaw remains present in thousands of internet-accessible systems.
BMC systems provide administrators with remote access to servers for maintenance, monitoring, and management tasks, even when the operating system is offline. These out-of-band management interfaces are critical infrastructure components in data centers, making them high-value targets for attackers. The exposure of authentication hashes before login bypasses normal security controls and could enable unauthorized access to sensitive server infrastructure.
The technical nature of the vulnerability centers on improper handling of authentication credentials during the login sequence. By exposing password hashes before authentication completes, attackers can capture these hashes and potentially crack them offline using brute-force or dictionary attacks. Once compromised, BMC access grants attackers extensive control over physical servers, including the ability to modify firmware, access console output, and manipulate hardware settings.
The widespread exposure of these systems represents a significant risk to enterprise and cloud infrastructure. With 24,000 vulnerable interfaces accessible from the internet, attackers have numerous potential entry points into critical data center environments. Successful exploitation could lead to data theft, service disruption, ransomware deployment, or long-term persistent access to server infrastructure.
Security teams should immediately inventory all BMC and remote management interfaces in their environments. Best practices include removing these systems from direct internet access, placing them behind VPNs or jump hosts, implementing strong authentication mechanisms, and applying all available security updates. Organizations should also monitor BMC access logs for suspicious activity and consider changing default credentials on all management interfaces.
Source: https://www.securityweek.com/decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks/


