Thousands of Servers Leak Authentication Password Hashes via 20 Year-Old Vuln in BMC Interface

Researchers have uncovered more than 24,000 servers leaking authentication password hashes from a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. 

Lava HQ has a great write up about it here: https://lavahq.io/research/bmc-exposure-alert

Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:

“The flaw CVE-2013-4786 exposes is in the IPMI RAKP handshake spec, and has been around for 20 years. It returns the password hash enabling offline brute-force attacks you don’t see. The researchers cracked HPE factory passwords in about a day on a cheap M3 Mac. A stronger, non-default password buys more time, but the protocol still hands over the hash; rotation only treats the symptom and the offline brute-force attack is still effective. Vulnerable enterprises should remove these management interfaces from the public internet, update all their passwords and usernames to be complex and non-default, and disable legacy IPMI authentication.”

If you think you might be affected by this, the Lava HQ article has instructions as to how to test, and how to fix this issue. I strongly recommend that you follow these directions ASAP.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading