Home/News/24,000 Servers Leak Passwords Via 20-Year-Old BMC Flaw
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

24,000 Servers Leak Passwords Via 20-Year-Old BMC Flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes, a critical security vulnerability stemming from a 20-year-old flaw in their Baseboard Management Controller (BMC) interfaces. The BMC is a specialized microcontroller embedded in server hardware that provides out-of-band management capabilities, allowing administrators to monitor and control servers remotely, even when the main operating system is offline. This includes functions like power cycling, hardware monitoring, and remote console access, typically accessed via a web interface. The vulnerability, which has been present for approximately two decades, allows unauthorized access to these password hashes, which are often stored in a format that can be cracked to reveal the actual passwords. This exposure significantly increases the risk of unauthorized access to sensitive server infrastructure and data.

The discovery highlights a persistent issue with legacy hardware and the slow pace of security updates for embedded systems. Many organizations continue to rely on older server hardware that may not have received critical security patches for their BMC components. The exposure of password hashes means that attackers can potentially bypass authentication mechanisms and gain control over these servers. This could lead to data breaches, system compromise, or the use of compromised servers in botnets for further malicious activities. The sheer number of affected servers indicates a widespread problem across various industries and data center environments.

Security researchers have identified that the vulnerability allows for the retrieval of password hashes through various means, often by exploiting weak default credentials or unpatched firmware. Once these hashes are obtained, they can be subjected to brute-force attacks or dictionary attacks using specialized software to decipher the original passwords. The impact of such a breach can be severe, as BMCs often have privileged access to the underlying hardware and network, potentially allowing attackers to pivot to other systems within the network. The long-standing nature of the vulnerability suggests that many organizations may be unaware of the risk, as BMC interfaces are not always actively monitored for security threats in the same way as operating systems or network devices.

This incident serves as a stark reminder of the importance of regular security audits, firmware updates for all hardware components, and the principle of least privilege for management interfaces. Organizations are advised to immediately assess their server infrastructure for vulnerable BMCs, change default credentials, ensure firmware is up-to-date, and restrict access to BMC interfaces to authorized personnel only. The continued reliance on older hardware, coupled with the critical nature of BMC functionality, creates a persistent attack surface that requires diligent management and proactive security measures to mitigate the risks of widespread compromise.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next