{"id":16521,"date":"2026-07-29T01:35:57","date_gmt":"2026-07-29T01:35:57","guid":{"rendered":"https:\/\/newestek.com\/?p=16521"},"modified":"2026-07-29T01:35:57","modified_gmt":"2026-07-29T01:35:57","slug":"a-13-year-old-flaw-is-exposing-tens-of-thousands-of-data-center-management-systems","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16521","title":{"rendered":"A 13-year-old flaw is exposing tens of thousands of data center management systems"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">The \u2018no man\u2019s land\u2019 beneath the OS on enterprise servers is becoming the malicious actors\u2019 next target.<\/p>\n<p class=\"wp-block-paragraph\">Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades-old protocols and susceptible to a vulnerability published 13 years ago, according to data center security company Lava.<\/p>\n<p class=\"wp-block-paragraph\">Lava\u2019s red team researchers were able to <a href=\"https:\/\/www.csoonline.com\/article\/647906\/new-vulnerabilities-mean-its-time-to-review-your-lights-out-server-bmc-interfaces.html\" target=\"_blank\">hack into BMCs<\/a>, which provide out-of-band remote control over servers without the need for physical access, within minutes by guessing basic passwords. BMCs on Supermicro and HPE servers were among the most impacted.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBMCs control critical infrastructure, yet they often receive far less monitoring and protection than the systems they manage,\u201d <a href=\"https:\/\/il.linkedin.com\/in\/michael-katchinskiy\" target=\"_blank\" rel=\"noreferrer noopener\">Michael Katchinskiy<\/a>, Lava\u2019s head of security research, explained in a <a href=\"https:\/\/lavahq.io\/research\/bmc-exposure-alert#why-bmc-compromise-is-especially-dangerous-in-ai-infrastructure\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>. \u201cMost security tools monitor the operating system, kernel, containers, and workloads.\u201d <\/p>\n<p class=\"wp-block-paragraph\">But BMCs operate outside that trust boundary, he said, \u201cgiving an attacker control beneath the host while remaining largely invisible to the tools designed to protect it.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-attackers-can-exploit-bmc-weaknesses\">How attackers can exploit BMC weaknesses<\/h2>\n<p class=\"wp-block-paragraph\">As the name \u2018baseboard\u2019 would imply, BMCs are specialized micro-controllers embedded in server platforms that operate independently of the host system\u2019s main CPU, memory, and operating system (OS). This gives admins the ability to do out-of-band management and troubleshooting of servers, update firmware, change configurations, and read hardware sensors, among other actions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn practice, the BMC is one of the most privileged control points in a data center,\u201d Katchinskiy noted.<\/p>\n<p class=\"wp-block-paragraph\">But BMCs can expose management planes such as the 22-year-old out-of-band IPMI, the newer HTTPS-based Redfish, browser-based admin interfaces, and remote console features. In many cases, these share the same database and even the same credentials.<\/p>\n<p class=\"wp-block-paragraph\">The culprit enabling the current attacks is a vulnerability in the <a href=\"https:\/\/www.computerworld.com\/article\/1391339\/many-servers-expose-insecure-out-of-band-management-interfaces-to-the-internet.html\" target=\"_blank\">IPMI 2.0 authentication protocol<\/a>, tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2013-4786\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2013-4786<\/a>, that was published in 2013.<\/p>\n<p class=\"wp-block-paragraph\">Lava\u2019s researchers discovered 36,872 BMCs reachable from the public internet still exposing IPMI. Of those, 66% (24,650) disclosed authentication hashes, scrambled versions of passwords that are stored and later used to authenticate users. Hackers can take them offline to examine and recover original passwords.<\/p>\n<p class=\"wp-block-paragraph\">The researchers tested hashes against common wordlists and found that more than 30% of the hashes were linked to \u201creused, factory-set, or predictably formatted\u201d passwords. These matches were discovered in minutes, and often during the first pass. And nearly 17% of BMCs accepted an empty username field with a weak password.<\/p>\n<p class=\"wp-block-paragraph\">Interestingly, <a href=\"https:\/\/www.networkworld.com\/article\/4063464\/new-supermicro-bmc-vulnerabilities-open-servers-to-malicious-attacks-on-firmware.html\" target=\"_blank\">Supermicro<\/a>, which is in wide use across data centers, GPU infrastructures, and hosted environments, accounted for more than half of responding BMCs, but their credentials did not match passwords in the researchers\u2019 wordlist.<\/p>\n<p class=\"wp-block-paragraph\">This was \u201cexpected,\u201d the researchers note, because in 2019 Supermicro replaced a shared admin password on impacted products with unique, factory-issued passwords which consisted of 10 uppercase letters printed on a chassis label.<\/p>\n<p class=\"wp-block-paragraph\">The researchers reported their findings to impacted parties and to Supermicro, which said it would review potential improvements to its default password policy for future hardware revisions. Lava said that Supermicro has since fixed the exposure. <\/p>\n<p class=\"wp-block-paragraph\">Lava has also created an interactive map of the internet-exposed BMCs it uncovered.<\/p>\n<h2 class=\"wp-block-heading\" id=\"why-this-attack-method-is-dangerous\">Why this attack method is dangerous<\/h2>\n<p class=\"wp-block-paragraph\">BMCs sit a layer below that which many security products monitor, on shared out-of-band management networks where administrative credentials are often reused. Thus, malicious changes made to BMCs or other platform hardware are able to survive OS reinstalls, disk replacements, and standard incident response procedures, Katchinskiy noted.<\/p>\n<p class=\"wp-block-paragraph\">The risk is \u201cespecially pronounced\u201d in neocloud and GPU cloud environments, he said. AI infrastructure can span thousands of GPUs on shared management networks, with joint storage, high-speed interconnects, and multi-tenant tooling.<\/p>\n<p class=\"wp-block-paragraph\">He pointed out that, while a customer may rent their own dedicated servers, they are still connected to shared, provider-managed, out-of-band networks where orchestration and provisioning services, credential stores, and admin tools span infrastructure used by numerous joint customers.<\/p>\n<p class=\"wp-block-paragraph\">That means, he noted, that the risk extends well beyond a single server, and attackers can gain a foothold to reach larger portions of data center infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">In the environments examined, BMC management networks \u201clacked effective segmentation, access controls, and monitoring,\u201d Katchinskiy said. \u201cA single compromised BMC can therefore become a path to additional servers, critical infrastructure, and customer workloads.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"why-bmcs-are-so-often-overlooked\">Why BMCs are so often overlooked<\/h2>\n<p class=\"wp-block-paragraph\">There are \u201ccountless examples\u201d of hardware and software tools that don\u2019t get patched because IT or security teams determine that, while they are vulnerable, threat actors can\u2019t exploit them, noted <a href=\"https:\/\/www.linkedin.com\/in\/dbshipley\/\" target=\"_blank\" rel=\"noreferrer noopener\">David Shipley<\/a> of Beauceron Security. For instance, there\u2019s a commonly-held notion that if a server or piece of software is air-gapped, meaning it is not network connected or not connected to the internet, it is safe.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf it\u2019s overlooked, it\u2019s likely because it sits in this weird in-between space between teams,\u201d he said. It\u2019s not really part of networking, and it exists before the OS is booted, so it\u2019s not under the domain of the system administrators.<\/p>\n<p class=\"wp-block-paragraph\">Thus, getting access is \u201cso simple,\u201d Shipley noted, and attackers can do \u201call kinds of not fun things in theory.\u201d<\/p>\n<p class=\"wp-block-paragraph\">For instance, they can power off devices, which can shut down a company\u2019s servers. Second, they could potentially take control of a server by \u201creimaging it and having their own OS in play,\u201d although that should be detected pretty quickly, he pointed out. Third, they can be persistent.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt gives them a place to live on a network and think about finding other holes to exploit as vulnerabilities,\u201d said Shipley.<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-simple-fix\">A \u2018simple fix\u2019<\/h2>\n<p class=\"wp-block-paragraph\">There\u2019s a \u201csimple\u201d fix to this problem, according to Katchinskiy: IPMI and Redfish should never be exposed to the public internet.<\/p>\n<p class=\"wp-block-paragraph\">To keep attackers out of BMCs, defenders should:<\/p>\n<ul class=\"wp-block-list\">\n<li>Replace factory-issued passwords.<\/li>\n<li>Restrict BMC access to a dedicated private management network, VPN, or other controlled path.<\/li>\n<li>Apply network access controls so that only approved admins can reach BMC interfaces.<\/li>\n<li>Disable \u201clegacy or weak\u201d options like IPMI 1.5, anonymous accounts, or, worse, authentication that grants access or tokens without requesting a password, secret, or login.<\/li>\n<li>Monitor management networks and production workloads separately.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">And, Katchinskiy emphasized, \u201corganizations must treat management layers as critical security boundaries: Isolate them, remove public exposure, rotate factory credentials, and monitor them continuously.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The \u2018no man\u2019s land\u2019 beneath the OS on enterprise servers is becoming the malicious actors\u2019 next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades-old protocols and susceptible to a vulnerability published 13 years ago, according to data center security company Lava. Lava\u2019s red team researchers were able to hack&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16521\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16521","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16521"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16521\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}