Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US walks out of UN Security Council meeting during France’s remarks

    July 28, 2026

    Domestic Abuse Allegations Rock Max Miller’s Ohio House Race

    July 28, 2026

    Trump Asks Supreme Court to Overturn $83.3 Million Award in Carroll Defamation Case

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US walks out of UN Security Council meeting during France’s remarks
    • Domestic Abuse Allegations Rock Max Miller’s Ohio House Race
    • Trump Asks Supreme Court to Overturn $83.3 Million Award in Carroll Defamation Case
    • Laura Loomer’s Reversal on Ukraine Stirs Up the MAGA Civil War
    • Fireworks AI Releases Fireworks Nexus: A Drop-In Routing and Cost-Control Layer That Moves Routine Coding Work to Open-Weight Models
    • CubePilot drone software dev hit by DNS hijacking to intercept traffic
    • Inside the brutal 2-minute flash crash sending a $400M South Korean market plunging on Hyperliquid
    • Twisted laser light can tell mirror-image molecules apart
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Flaw From 2002 Exposes Data Centers to Server Takeover

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Some 24,000 Internet-exposed server management controllers are vulnerable to a more than 20-year-old flaw that gives attackers a way to crack authentication credentials and gain privileged access to the underlying servers.

    The issue can evade conventional security tools because these management controllers operate independently of the server’s operating system, kernel, containers, and workloads, and are therefore nearly invisible at those layers.

    Researchers at Lava discovered the flaw when researching Internet-exposed Baseboard Management Controllers (BMCs) for vulnerabilities and said it found evidence of attackers having exploited the issue in the wild.

    A Highly Privileged Interface

    A BMC is a small, dedicated processor built into a server’s motherboard. It operates separately from the server’s main processor and operating system and gives administrators a way to remotely monitor and manage server hardware and functions like rebooting or powering servers on and off and checking system health. Admins can access the console even when the OS is down or the server is otherwise unresponsive.

    Related:Attackers Are Learning to Live Off the AI Toolchain

    Administrators typically access BMCs through Intelligent Platform Management Interface (IPMI), an older protocol for remote hardware management; and Redfish, a newer API for managing server hardware over HTTPS and Web-based administrative interfaces. They can also use remote console or virtual media features for remotely accessing the server screen or attaching storage media, depending on the server platform.

    Because it operates below the OS, BMCs have extensive access to the underlying hardware. “A compromised BMC puts defenders in a uniquely difficult position,” Lava researcher Michael Katchinskiy wrote. “Most security tools monitor the operating system, kernel, containers, and workloads. The BMC operates outside that trust boundary, giving an attacker control beneath the host while remaining largely invisible to the tools designed to protect it.”

    The issue that Lava discovered involves CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol that can cause a BMC to return password-derived authentication hashes to an unauthenticated client before the login process is complete. The flaw was introduced with the release of IPMI 2.0 in 2004 but was disclosed and had a CVE assigned to it, but not until 2013.

    An attacker who can reach UDP port 623 — the standard port that IPMI uses — without authenticating can obtain the hash and use it to try and brute force the password offline. “Unlike repeated online login attempts, this process does not require a new request to the BMC for every password candidate,” making it especially useful for cracking weak, reused, factory-set and predictably formatted passwords, Katchinskiy said.

    Related:When AI Attacks: OpenAI Models Autonomously Hack Hugging Face

    Thousands of Potentially Vulnerable Systems

    In its scan, Lava found 24,650 BMC endpoints responding with password-derived authentication material that attackers could potentially use to guess their passwords offline. Of these, 6,240 accepted empty usernames paired with weak passwords, while 2,340 had named accounts such as ADMIN or root whose passwords matched common wordlists. In many instances Lava was able to find passwords in minutes. The researchers also found that some default passwords not present in common wordlists — including those used by Supermicro BMCs — could potentially be cracked because they followed predictable formats.

    Yakir Kadkoda, chief technology officer (CTO) and cofounder at Lava, describes the issue as a serious one because of how a BMC is one of the most privileged control points in a data center. “It operates independently of the operating system and can provide remote console access, power control, virtual media, firmware management, and low-level configuration,” he says in comments to Dark Reading.

    Related:Hacker Turns AI Jailbreaks Into Offensive Attack Platform

    In a realistic attack, an adversary could recover a weak or predictable BMC password, gain initial access to the exposed server, and use it as a foothold to compromise additional servers and management systems by moving laterally through the data center’s out-of-band management network. “Because these networks are often poorly segmented and lightly monitored, the attacker may be able to reach additional BMCs, storage systems, provisioning infrastructure, and internal management services. In a GPU cloud, this could also create a path into shared or multitenant infrastructure,” he cautions.

    Unnamed Manufacturer Falls Prey

    In a worst case scenario, an attacker could gain a highly privileged foothold inside the data center management plane from which they could remotely control servers, modify low-level configurations, interfere with firmware, access storage and internal systems, deploy ransomware, or remain undetected for long periods, Kadkoda says. “Recovery could require firmware re-flashing, platform-level validation, vendor-assisted remediation, or even hardware replacement.”

    According to Kadkoda, Lava has found clear evidence of attackers compromising Internet-exposed BMC interfaces. “During the research, we identified compromised systems belonging to one of the world’s largest automotive component manufacturers. Multiple exposed servers displayed ransomware notes and payment demands, indicating that the company was being targeted as part of an active attack campaign.”

    In another instance, Lava found an exposed HPE BMC displaying a ransom note, confirming that an unauthorized party had gained access to the management interface.

    The immediate step that organizations can take to mitigate risk is to remove BMC and IPMI interfaces from the public Internet. But that alone is not sufficient, he cautions. “Organizations should isolate BMCs on a dedicated management network, restrict access through tightly controlled administrative paths, replace factory and reused credentials, disable insecure legacy features, and continuously monitor the out-of-band network.”

    centers data exposes Flaw server takeover
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CubePilot drone software dev hit by DNS hijacking to intercept traffic

    Samsung’s AI-powered glasses could be looking at your data

    Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

    ‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates

    Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

    Is Your SSO Protected Against Modern Credential Attacks?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US walks out of UN Security Council meeting during France’s remarks

    July 28, 2026

    Domestic Abuse Allegations Rock Max Miller’s Ohio House Race

    July 28, 2026

    Trump Asks Supreme Court to Overturn $83.3 Million Award in Carroll Defamation Case

    July 28, 2026

    Laura Loomer’s Reversal on Ukraine Stirs Up the MAGA Civil War

    July 28, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US walks out of UN Security Council meeting during France’s remarks

    July 28, 2026

    Domestic Abuse Allegations Rock Max Miller’s Ohio House Race

    July 28, 2026

    Trump Asks Supreme Court to Overturn $83.3 Million Award in Carroll Defamation Case

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.