Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Thousands of Data Centers Exposed to Attacks Due to Decades-Old BMC Vulnerability

A 22-year-old security flaw in Baseboard Management Controller (BMC) management processors has put thousands of data centers at risk of compromise. The vulnerability, which affects nearly 37,000 internet-exposed server-management interfaces, allows attackers to obtain password hashes and crack them offline.

The issue stems from a weakness in the IPMI authentication protocol, introduced in 2004 as part of the IPMI 2.0 specification. This flaw, known as CVE-2013-4786, enables attackers to request an HMAC-SHA1 authentication code from a BMC during login attempts. By doing so, they can test password guesses offline without needing to repeatedly attempt online logins.

This vulnerability is particularly concerning because it affects many data centers that rely on BMCs for server management operations. These controllers enable administrators to power-cycle hosts, perform firmware updates, and configure low-level platform settings – all without requiring a working operating system. With the IPMI protocol allowing authentication through several management surfaces, including web interfaces and HTTPS-based APIs, the risk of unauthorized access is amplified.

According to data center security firm Lava, nearly 37,000 internet-exposed server-management interfaces are running the IPMI protocol, with over 24,000 of them disclosing password-derived authentication hashes before login. Furthermore, an alarming number of hosts – around 6,240 – were found accepting empty usernames accompanied by weak passwords.

Moreover, Lava discovered that some BMCs used predictable factory-issued password formats and were even vulnerable to constrained password guessing attacks. This, combined with the widespread use of common passwords and default credentials, creates a perfect storm for attackers seeking to exploit this vulnerability.

The broader security implications are equally concerning: “This vulnerability exposes a security gap in the data center management plane,” notes Lava. “BMCs control critical infrastructure yet often receive far less monitoring and protection than the systems they manage.” If left unaddressed, this vulnerability can turn an exposed BMC into a privileged foothold across the management network.

To mitigate these risks, administrators should prioritize patching affected BMCs and enforcing robust password policies. This includes using complex passwords that are not easily guessable and avoiding the use of default credentials or weak, reused passwords. Additionally, organizations should consider implementing proactive monitoring for unusual login attempts or changes in BMC configuration to detect potential attacks early on.

Ultimately, this vulnerability serves as a stark reminder of the importance of maintaining secure data center operations and prioritizing the protection of privileged systems like BMCs.


Source: SecurityWeek — 2026-08-04