THE article highlights a significant security vulnerability affecting over 24,000 Internet-exposed Baseboard Management Controllers (BMCs) that stem from a flaw over 20 years old (CVE-2013-4786). This vulnerability allows attackers to potentially crack authentication credentials offline, compromising server management systems without being detected by regular security measures.
Researchers from Lava identified the flaw and noted existing exploits in the wild, demonstrating the critical risk BMCs pose due to their privileged access to server hardware. Misconfigured systems, weak passwords, and common username practices compound the issue, emphasizing the need for organizations to isolate BMCs from public access and implement better security practices.