Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Overview
A long-standing vulnerability in Baseboard Management Controllers (BMC) has been discovered, exposing over 24,000 server-management interfaces to potential attacks. This flaw allows unauthorized users to access sensitive authentication hashes before login, significantly increasing the risk of a breach. Data centers that utilize these interfaces, which are common in many server setups, are particularly vulnerable. This situation raises serious concerns about the security of critical infrastructure, as attackers could exploit these weaknesses to gain control over systems. Organizations need to assess their BMC configurations and take immediate action to protect their data centers from possible exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Baseboard Management Controllers (BMC) across various server brands and models with internet-accessible interfaces.
- Action Required: Organizations should review their BMC configurations, apply available patches, and restrict internet access to these interfaces.
- Timeline: Disclosed on October 2023
Original Article Summary
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.
Impact
Baseboard Management Controllers (BMC) across various server brands and models with internet-accessible interfaces.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on October 2023
Remediation
Organizations should review their BMC configurations, apply available patches, and restrict internet access to these interfaces.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability, Critical.