An outdated security flaw in Baseboard Management Controller (BMC) systems is jeopardizing numerous data centers, according to a recent report by cybersecurity firm Lava. This vulnerability, which has persisted for over two decades, affects the management processors of BMCs, integral to most server platforms.
The Role of BMCs in Data Centers
BMCs are pivotal components that facilitate server management tasks even when the operating system is inactive. They serve as crucial control hubs in data centers, enabling administrators to execute operations such as power cycling, firmware updates, and hardware monitoring through various management interfaces.
These interfaces include the IPMI protocol, the Redfish API, and web-based administrative platforms. Often, these interfaces share user credentials, making them susceptible to security breaches if one is compromised.
Impact of the IPMI Protocol Vulnerability
Lava’s findings indicate that approximately 37,000 server-management interfaces exposed to the internet utilize the IPMI protocol, with more than 24,000 leaking authentication hashes. The key issue, identified as CVE-2013-4786, involves the IPMI 2.0 authentication protocol from 2004, allowing attackers to capture and decode password hashes offline.
This vulnerability is exploited by obtaining HMAC codes from RAKP message responses, potentially allowing unauthorized remote access through UDP port 623. Attackers can crack weak or default passwords without the need for repeated login attempts.
Security Risks and Recommendations
The report also highlights that over 6,000 hosts accept weak passwords and empty usernames, while some use predictable factory-issued passwords. These weaknesses underscore a significant security gap in data center management, as BMCs often lack adequate monitoring compared to the infrastructure they oversee.
With the advent of advanced GPU cracking techniques and predictable passwords, a compromised BMC could provide a stealthy entry point into the network’s management plane. The report emphasizes the necessity for enhanced security measures and regular updates to mitigate these risks.
As the threat landscape evolves, addressing these vulnerabilities is crucial to safeguarding critical infrastructure from potential cyber threats.
