20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
Key Takeaways A vulnerability dating back two decades (CVE-2013-4786) in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to seize control of thousands of data...
Key Takeaways
- A vulnerability dating back two decades (CVE-2013-4786) in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to seize control of thousands of data center servers.
- The flaw impacts Baseboard Management Controllers (BMCs) by exposing password-derived authentication data, enabling offline password cracking.
- Over 36,000 publicly accessible IPMI interfaces have been identified, with a significant percentage vulnerable, including systems from major vendors like Supermicro and HPE.
- A successful compromise grants deep control over physical servers, bypassing standard security measures and potentially leading to widespread network infiltration.
- Organizations must urgently secure BMCs by removing them from public exposure, rotating passwords, and implementing network segmentation.
Critical Vulnerability Threatens Data Center Integrity via IPMI
Cybersecurity researchers have issued a stark warning regarding a pervasive, two-decade-old vulnerability within the Intelligent Platform Management Interface (IPMI) protocol. This critical flaw could grant malicious actors rapid, unauthorized control over thousands of internet-exposed data center servers, potentially within minutes.
Table Of Content
The Pervasive Reach of Baseboard Management Controllers
The core of the issue lies with Baseboard Management Controllers (BMCs). These are specialized, highly privileged processors designed for remote management of physical servers, even when the primary operating system is offline. BMCs offer extensive control capabilities, including system reboots, virtual media mounting, remote console access, firmware updates, and modification of low-level hardware configurations.
Analysis has revealed 36,872 publicly accessible server management interfaces utilizing IPMI on UDP port 623. Alarmingly, 24,650 of these (66.9%) were found to expose password-derived authentication data even before a successful user login. This behavior is directly linked to CVE-2013-4786, a long-standing vulnerability within the IPMI 2.0 Remote Authenticated Key-Exchange Protocol. The flaw permits an unauthenticated attacker to acquire an HMAC-SHA1 value, which is generated using the target account’s password.
This exposure allows attackers to attempt offline password recovery, a method that circumvents typical security measures such as account lockouts and security alerts that would otherwise trigger with repeated failed login attempts.
Widespread Exposure and Exploitation Risk
LavaHQ researchers reported that a significant portion—over 30%—of the recovered authentication hashes were associated with weak, commonly used, or easily guessable passwords. Specifically, 6,240 interfaces were found to expose authentication material for empty usernames combined with weak password candidates. Furthermore, 2,340 systems employed common named accounts, such as “ADMIN” or “root,” with passwords readily available in public wordlists. The exposed interfaces included modern systems from prominent hardware vendors, including Supermicro and HPE.
Some of the affected servers are operated by GPU and bare-metal cloud providers, where BMCs frequently reside on shared management networks supporting high-value AI infrastructure. Supermicro systems constituted more than half of the responsive BMCs in the analyzed dataset. Since 2019, certain Supermicro platforms have utilized unique factory passwords, typically ten uppercase letters printed on a chassis label. While unique, this predictable format creates a limited search space of 2610 combinations. Researchers noted that a determined attacker with an eight-GPU system could exhaust this entire password space in approximately one hour.
HPE iLO systems face a comparable risk. Their factory-issued iLO credentials consist of eight uppercase letters and numbers, resulting in a keyspace of 368 combinations. Researchers demonstrated that a modern multi-GPU system could search this entire space in approximately 32 seconds for a captured authentication response.
The Grave Consequences of a BMC Compromise
A compromised BMC presents severe risks, primarily because the controller operates at a layer beneath the server’s operating system, rendering it largely invisible to most endpoint security tools. An attacker with BMC access gains the ability to power off systems, access virtual consoles, modify firmware, exfiltrate data via mounted media, or establish persistent backdoors that survive operating system reinstallation.
The threat extends beyond individual servers. In many operational environments, BMC interfaces share management networks characterized by poor segmentation, credential reuse, and inadequate monitoring. A single compromised controller can thus become a gateway to other BMCs, critical infrastructure services, and sensitive customer workloads.
LavaHQ researchers found evidence of active exploitation, noting one internet-exposed HPE iLO interface displaying a ransom note demanding 0.3 BTC. This discovery strongly suggests that attackers have already successfully compromised the management plane of these systems.
What You Should Do
- Remove from Public Internet: Immediately ensure all IPMI interfaces are removed from direct exposure to the public internet.
- Block UDP Port 623: Implement firewall rules to block UDP port 623 at the network perimeter.
- Rotate Passwords: Promptly change all factory-issued BMC passwords to strong, unique credentials.
- Disable Insecure Authentication: Deactivate any insecure or legacy authentication options within BMC configurations.
- Network Segmentation: Isolate BMCs onto dedicated, highly segmented management networks.
- Restrict Access: Implement strict access controls, utilizing VPNs, bastion hosts, VLANs, and granular firewall rules to limit who can access BMCs.
- Regular Auditing: Conduct regular audits of BMC configurations and network exposure to identify and remediate vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.