How Researchers Reached Thousands of Data Centers in Minutes via a 20-Year-Old IPMI Flaw
AccBalanced · x · 2026-09-03
Lava researchers show how a 20-year-old vulnerability let them reach bare-metal servers across thousands of data centers: of 36,872 internet-exposed IPMI interfaces, 24,650 leak password-derived hashes pre-auth due to CVE-2013-4786, and over 30% of recovered passwords fell to common wordlists or predictable factory-sticker formats. A BMC grants control independent of the OS — one exposed controller can risk an entire GPU fleet. SemiAnalysis' Jordan Nanos adds that neoclouds serving banks, telcos, and national defense are years out of date with no patching or customer-notification processes. The team released the BMCRadar exposure map and the FORGE security framework.
More from Infra
- Microsoft to Disclose Azure Revenue Quarterly in Major Financial Reporting Overhaul — tomwarren · 2026-09-03
- HyperspaceDB v3.1.4: 1-bit ADC gets 107× search speedup, ships Mem0 drop-in replacement — Sam_YARINK · 2026-09-03
- Tesla targets one Cybercab every 5 seconds from a single production line — XFreeze · 2026-09-03
- New paper debunks RL batch scaling: 2.29x throughput doesn't mean faster learning — teortaxesTex · 2026-09-03
- PyTorch MPS Linear Algebra Called 'Trash': Slow and Improperly Batched — ducha_aiki · 2026-09-03
- Anthropic Signs $35 Billion Cloud Deal With Lambda to Scale Claude — The Decoder · 2026-09-03