
A 13-year-old flaw is exposing tens of thousands of data center management systems
The ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target.
Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades-old protocols and susceptible to a vulnerability published 13 years ago, according to data center security company Lava.
Lava’s red team researchers were able to hack into BMCs, which provide out-of-band remote control over servers without the need for physical access, within minutes by guessing basic passwords. BMCs on Supermicro and HPE servers were among the most impacted.
“BMCs control critical infrastructure, y...