CISOOnline

A 13-year-old flaw is exposing tens of thousands of data center management systems

Why this attack method is dangerous

BMCs sit a layer below that which many security products monitor, on shared out-of-band management networks where administrative credentials are often reused. Thus, malicious changes made to BMCs or other platform hardware are able to survive OS reinstalls, disk replacements, and standard incident response procedures, Katchinskiy noted.

The risk is “especially pronounced” in neocloud and GPU cloud environments, he said. AI infrastructure can span thousands of GPUs on shared management networks, with joint storage, high-speed interconnects, and multi-tenant tooling.

He pointed out that, while a customer may rent their own dedicated servers, they are still connected to shared, provider-managed, out-of-band networks where orchestration and provisioning services, credential stores, and admin tools span infrastructure used by numerous joint customers.



Source link