← Back to Tech & Science

Global Servers Exposed as Researchers Identify Critical IPMI Vulnerability Affecting Tens of Thousands

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON — Cybersecurity researchers have identified a critical vulnerability affecting more than 24,650 internet-exposed servers worldwide, exposing them to potential unauthorized access. The flaw allows attackers to retrieve password hashes from Baseboard Management Controllers (BMCs) before any login attempt is made, enabling offline cracking of credentials.

The discovery centers on the Intelligent Platform Management Interface version 2.0 specification, specifically a defect tracked as CVE-2013-4786. The vulnerability permits malicious actors to intercept authentication hashes transmitted by BMCs during the initial handshake phase. Because these hashes are disclosed prior to successful login verification, attackers can download them and attempt to crack passwords using brute-force methods on their own systems without triggering intrusion detection alerts or locking out accounts.

Researchers from Lava reported the findings in coordination with The Hacker News. Their global scan revealed that the exposed devices are concentrated primarily in the United States, Germany, China, the Netherlands, and the United Kingdom. These BMCs serve as critical infrastructure for managing server hardware remotely, controlling functions such as power cycling, firmware updates, and system monitoring. Compromise of these controllers could grant attackers complete control over physical servers, potentially allowing them to install malware, steal data, or disrupt essential services.

The vulnerability stems from a design flaw in the IPMI v2.0 specification itself rather than a specific software bug within individual vendors' implementations. Consequently, no patch exists for this issue across affected hardware manufacturers. The defect has persisted since 2013 but remains unaddressed by many organizations that have left their management interfaces exposed to the public internet.

Security experts warn that without immediate mitigation, these systems remain vulnerable to exploitation. Because a software fix is not available due to the nature of the specification flaw, administrators must rely on network-level defenses. Recommended measures include isolating BMCs from direct internet access, implementing strict firewall rules to restrict traffic to known management IP addresses, and disabling remote out-of-band management features where they are not strictly necessary.

The scale of exposure raises concerns about the resilience of critical infrastructure globally. While many organizations have begun scanning their networks for exposed ports associated with IPMI services, the lack of a vendor patch means that any device relying on this specification remains at risk if network segmentation fails. Questions remain regarding how long these vulnerabilities will persist without a fundamental change to the industry standard or widespread adoption of alternative management protocols.

Discussion

0 / 2000