news.mlab.sh
Back to the feed
threat-intel

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

High
Image: The Hacker News
Summary

A significant vulnerability, CVE-2013-4786, has been exposed due to a 20-year-old flaw in the IPMI 2.0 specification, resulting in over 36,000 internet-exposed BMCs revealing password hashes. This allows attackers to conduct offline password cracking and potentially deploy malware, especially in rapidly expanding AI data centers. The vulnerability stems from a 20-year-old weakness that has been exacerbated by advancements in GPU cracking and the increasing value of bare-metal infrastructure.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.