Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Old BMC Flaw Threatens Thousands of Data Centers

Old BMC Flaw Threatens Thousands of Data Centers

Posted on August 4, 2026 By CWS

An outdated security flaw in Baseboard Management Controller (BMC) systems is jeopardizing numerous data centers, according to a recent report by cybersecurity firm Lava. This vulnerability, which has persisted for over two decades, affects the management processors of BMCs, integral to most server platforms.

The Role of BMCs in Data Centers

BMCs are pivotal components that facilitate server management tasks even when the operating system is inactive. They serve as crucial control hubs in data centers, enabling administrators to execute operations such as power cycling, firmware updates, and hardware monitoring through various management interfaces.

These interfaces include the IPMI protocol, the Redfish API, and web-based administrative platforms. Often, these interfaces share user credentials, making them susceptible to security breaches if one is compromised.

Impact of the IPMI Protocol Vulnerability

Lava’s findings indicate that approximately 37,000 server-management interfaces exposed to the internet utilize the IPMI protocol, with more than 24,000 leaking authentication hashes. The key issue, identified as CVE-2013-4786, involves the IPMI 2.0 authentication protocol from 2004, allowing attackers to capture and decode password hashes offline.

This vulnerability is exploited by obtaining HMAC codes from RAKP message responses, potentially allowing unauthorized remote access through UDP port 623. Attackers can crack weak or default passwords without the need for repeated login attempts.

Security Risks and Recommendations

The report also highlights that over 6,000 hosts accept weak passwords and empty usernames, while some use predictable factory-issued passwords. These weaknesses underscore a significant security gap in data center management, as BMCs often lack adequate monitoring compared to the infrastructure they oversee.

With the advent of advanced GPU cracking techniques and predictable passwords, a compromised BMC could provide a stealthy entry point into the network’s management plane. The report emphasizes the necessity for enhanced security measures and regular updates to mitigate these risks.

As the threat landscape evolves, addressing these vulnerabilities is crucial to safeguarding critical infrastructure from potential cyber threats.

Security Week News Tags:BMC vulnerability, CVE-2013-4786, Cybersecurity, data breach, data center security, HMAC authentication, IPMI protocol, Lava report, network security, password security, Redfish API, server management, UDP port 623, Vulnerability

Post navigation

Previous Post: North Korean Hackers Conceal Malware in Crypto Transfers
Next Post: DOUBLECUP’s Innovative Malware Delivery via Steganography

Related Posts

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits Security Week News
Stolen Credentials: A Persistent Threat to Cybersecurity Stolen Credentials: A Persistent Threat to Cybersecurity Security Week News
Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack Security Week News
RSAC 2026: Key Pre-Conference Announcements RSAC 2026: Key Pre-Conference Announcements Security Week News
Cybercriminals Exploit QEMU for Stealthy Attacks Cybercriminals Exploit QEMU for Stealthy Attacks Security Week News
Archetyp Dark Web Market Shut Down by Law Enforcement Archetyp Dark Web Market Shut Down by Law Enforcement Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploiting AI Agents: New Threat to Software Supply Chains
  • Gemini Attack Method Exposes Secrets, Risks PR Manipulation
  • DOUBLECUP’s Innovative Malware Delivery via Steganography
  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploiting AI Agents: New Threat to Software Supply Chains
  • Gemini Attack Method Exposes Secrets, Risks PR Manipulation
  • DOUBLECUP’s Innovative Malware Delivery via Steganography
  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark