threat-intel
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
High
Summary
A significant vulnerability, CVE-2013-4786, has been exposed due to a 20-year-old flaw in the IPMI 2.0 specification, resulting in over 36,000 internet-exposed BMCs revealing password hashes. This allows attackers to conduct offline password cracking and potentially deploy malware, especially in rapidly expanding AI data centers. The vulnerability stems from a 20-year-old weakness that has been exacerbated by advancements in GPU cracking and the increasing value of bare-metal infrastructure.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
