Security Techniques

IPMI Vulnerabilities on BMCs expose servers to attack

IPMI Vulnerabilities on BMCs expose servers to attack: Baseboard management controllers, embedded computers present in most servers, are vulnerable to a half dozen critical vulnerabilities that could enable an attacker to gain remote control over the host machine.

The vulnerabilities are in the Intelligent Platform Management Interface (IPMI) protocol specification that describes how BMCs communicate locally and across networks. The issues range from the ability to bypass authentication mechanisms, steal password hashes that can be brute-forced offline, to UPnP-based vulnerabilities that cannot be disabled and could lead to remote root compromises.