Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Old BMC Flaw Threatens Thousands of Data Centers

Old BMC Flaw Threatens Thousands of Data Centers

Posted on August 4, 2026 By CWS

An outdated security flaw in Baseboard Management Controller (BMC) systems is jeopardizing numerous data centers, according to a recent report by cybersecurity firm Lava. This vulnerability, which has persisted for over two decades, affects the management processors of BMCs, integral to most server platforms.

The Role of BMCs in Data Centers

BMCs are pivotal components that facilitate server management tasks even when the operating system is inactive. They serve as crucial control hubs in data centers, enabling administrators to execute operations such as power cycling, firmware updates, and hardware monitoring through various management interfaces.

These interfaces include the IPMI protocol, the Redfish API, and web-based administrative platforms. Often, these interfaces share user credentials, making them susceptible to security breaches if one is compromised.

Impact of the IPMI Protocol Vulnerability

Lava’s findings indicate that approximately 37,000 server-management interfaces exposed to the internet utilize the IPMI protocol, with more than 24,000 leaking authentication hashes. The key issue, identified as CVE-2013-4786, involves the IPMI 2.0 authentication protocol from 2004, allowing attackers to capture and decode password hashes offline.

This vulnerability is exploited by obtaining HMAC codes from RAKP message responses, potentially allowing unauthorized remote access through UDP port 623. Attackers can crack weak or default passwords without the need for repeated login attempts.

Security Risks and Recommendations

The report also highlights that over 6,000 hosts accept weak passwords and empty usernames, while some use predictable factory-issued passwords. These weaknesses underscore a significant security gap in data center management, as BMCs often lack adequate monitoring compared to the infrastructure they oversee.

With the advent of advanced GPU cracking techniques and predictable passwords, a compromised BMC could provide a stealthy entry point into the network’s management plane. The report emphasizes the necessity for enhanced security measures and regular updates to mitigate these risks.

As the threat landscape evolves, addressing these vulnerabilities is crucial to safeguarding critical infrastructure from potential cyber threats.

Security Week News Tags:BMC vulnerability, CVE-2013-4786, Cybersecurity, data breach, data center security, HMAC authentication, IPMI protocol, Lava report, network security, password security, Redfish API, server management, UDP port 623, Vulnerability

Post navigation

Previous Post: North Korean Hackers Conceal Malware in Crypto Transfers

Related Posts

Israel Leverages Iran’s Surveillance for Strategic Advantage Israel Leverages Iran’s Surveillance for Strategic Advantage Security Week News
Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications Security Week News
Tech Giants Unite to Tackle Online Scams and Fraud Tech Giants Unite to Tackle Online Scams and Fraud Security Week News
3.5 Million Affected by University of Phoenix Data Breach 3.5 Million Affected by University of Phoenix Data Breach Security Week News
Defend Against Identity Threats: Join Our Webinar Defend Against Identity Threats: Join Our Webinar Security Week News
Escape Secures  Million to Enhance Automated Pentesting Escape Secures $18 Million to Enhance Automated Pentesting Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers
  • Data Breach at Madera Hospital Affects 150,000 People
  • CISA Alerts on N-able N-central Vulnerability Exploitation
  • Critical Vulnerability in Check Point Systems Requires Immediate Patching

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers
  • Data Breach at Madera Hospital Affects 150,000 People
  • CISA Alerts on N-able N-central Vulnerability Exploitation
  • Critical Vulnerability in Check Point Systems Requires Immediate Patching

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark