Old Server Hardware Flaw Leaves Thousands of Data Centers Exposed
Security researchers have identified a decades-old vulnerability affecting Baseboard Management Controllers (BMCs), the specialised hardware used to remotely manage servers in data centers. More than 24,000 internet-accessible management interfaces were found to disclose authentication hashes before a user even logs in, giving attackers a potential foothold to crack passwords and gain unauthorised access.
BMCs operate at a low level, often outside the reach of standard security software, making them an attractive target for attackers seeking persistent, hard-to-detect access to critical infrastructure. Because this flaw has reportedly existed for years, many organisations may be unaware their server management systems are exposed to the internet at all.
While this issue primarily affects larger data centers and hosting providers, Australian small businesses that rely on cloud services, managed hosting, or co-located servers should ask their providers whether their infrastructure is affected and what steps are being taken to remediate it.