news.mlab.sh
Back to the feed
threat-intel

Flaw From 2002 Exposes Data Centers to Server Takeover

High
Image: Dark Reading
Summary

A 2002 vulnerability in the IPMI 2.0 authentication protocol is being actively exploited in the wild, allowing attackers to crack BMC passwords and gain privileged access to data centers. Researchers at Lava discovered that 24,650 BMC endpoints were exposing password-derived authentication material, with evidence of attacks targeting a major automotive component manufacturer and displaying ransomware notes. Due to the BMC's privileged access outside the OS, conventional security tools are largely ineffective, requiring a layered approach including network segmentation, credential changes, and disabling insecure features.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.