Vulnerabilità · 55 giorni fa
Le BMC esposte restano il varco più debole La superficie da difendere non è il sistema operativo, ma il piano di management fuori banda. Se un BMC espone l’hash prima del login, la password si può forzare offline e la difesa normale non vede né i tentativi né il superamento del confine reale: power, console, virtual media e firmware.
Lava ha contato 36.872 BMC raggiungibili da internet. Di queste, 24.650 restituivano materiale HMAC-SHA1 pre-auth legato a CVE-2013-4786 , e una quota ampia risultava recuperabile con wordlist comuni o password di fabbrica; il quadro includeva sistemi Supermicro, HPE e Dell, con vari casi ancora su credenziali di default.
Il punto critico è che la falla è nella specifica IPMI 2.0, quindi non esiste una patch pulita a livello di standard. Per gli ambienti con BMC esposti, il rischio resta quello di un takeover del server anche senza toccare l’OS.
NVD KEV
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100º percentile).
Cronologia Fonti 7 fonti che coprono questa storia
SecurityWeek 4 ago
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
CSO Online 28 lug
A 13-year-old flaw is exposing tens of thousands of data center management systems
Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system.
Dark Reading 28 lug
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
The Hacker News 28 lug
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.
Wiz Research 28 lug
The Security Risks Hiding Behind Exposed MCP Servers | Wiz Blog
Wiz Research reveals how unauthenticated MCP servers expose sensitive cloud databases, IAM, and internal tools to internet callers—and how to fix it.
Help Net Security 28 lug
Exposed BMCs hand out password hashes before login - Help Net Security
An exposed BMC IPMI vulnerability let 24,650 servers hand out password hashes before login.
BleepingComputer 28 lug
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Entità Part of the PlainSec briefing for 2026-08-04
Editions Storie correlate
Vulnerabilità · 55 giorni fa
Le BMC esposte restano il varco più debole La superficie da difendere non è il sistema operativo, ma il piano di management fuori banda. Se un BMC espone l’hash prima del login, la password si può forzare offline e la difesa normale non vede né i tentativi né il superamento del confine reale: power, console, virtual media e firmware.
Lava ha contato 36.872 BMC raggiungibili da internet. Di queste, 24.650 restituivano materiale HMAC-SHA1 pre-auth legato a CVE-2013-4786 , e una quota ampia risultava recuperabile con wordlist comuni o password di fabbrica; il quadro includeva sistemi Supermicro, HPE e Dell, con vari casi ancora su credenziali di default.
Il punto critico è che la falla è nella specifica IPMI 2.0, quindi non esiste una patch pulita a livello di standard. Per gli ambienti con BMC esposti, il rischio resta quello di un takeover del server anche senza toccare l’OS.
NVD KEV
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100º percentile).
Cronologia Fonti 7 fonti che coprono questa storia
SecurityWeek 4 ago
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
CSO Online 28 lug
A 13-year-old flaw is exposing tens of thousands of data center management systems
Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system.
Dark Reading 28 lug
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
The Hacker News 28 lug
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.
Wiz Research 28 lug
The Security Risks Hiding Behind Exposed MCP Servers | Wiz Blog
Wiz Research reveals how unauthenticated MCP servers expose sensitive cloud databases, IAM, and internal tools to internet callers—and how to fix it.
Help Net Security 28 lug
Exposed BMCs hand out password hashes before login - Help Net Security
An exposed BMC IPMI vulnerability let 24,650 servers hand out password hashes before login.
BleepingComputer 28 lug
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Entità Part of the PlainSec briefing for 2026-08-04
Editions Storie correlate