A critical security vulnerability affecting Baseboard Management Controllers (BMCs) in data centers, identified as CVE-2013-4786, exposes thousands of servers to potential compromise. BMCs, essential for server management, allow administrative access even without a functioning operating system. The IPMI protocol widely used for these controllers suffers from flaws enabling attackers to retrieve password hashes, facilitating offline cracking.
Roughly 37,000 server-management interfaces are exposed on the internet, with many disclosing weak or default passwords. This vulnerability poses a significant risk to data center security, as BMCs are often inadequately monitored.