Exposed BMCs Leak Password Hashes Due to IPMI Vulnerability

Exposed BMCs Leak Password Hashes Due to IPMI Vulnerability

First seen 28 Jul 2026, 15:16 UTC Feeds2.FeedburnerBleepingcomputernvd.nist.govlavahq.io 84% similarity 71.0

Article Content

Browse articles
ThreatCluster

Over 24,000 internet-exposed Baseboard Management Controllers (BMCs) are leaking authentication password hashes due to a vulnerability (CVE-2013-4786) in the IPMI 2.0 protocol, introduced in 2004. Researchers from Lava identified 36,872 servers with exposed management interfaces, with 24,650 disclosing password-derived hashes before login. Many of these hashes can be cracked using common wordlists and predictable factory passwords. The exposure is particularly concerning for Supermicro and HPE servers, which often use weak default credentials. The compromised BMCs allow attackers to gain control over physical servers, potentially affecting multiple tenants in shared environments. The risk is exacerbated by poor network segmentation and access controls in the management networks. This vulnerability poses a significant threat to data center infrastructure, as a single compromised BMC can serve as a foothold for broader attacks.

Key Points: • Over 24,000 BMCs are leaking password hashes due to CVE-2013-4786. • Many exposed servers use weak default credentials, making them easy targets. • Compromised BMCs can allow attackers to control physical servers and disrupt multiple tenants.

ThreatCluster AI How this analysis works

Timeline

2013-07-08
CVE-2013-4786 published
A vulnerability in the IPMI 2.0 authentication protocol was disclosed, allowing offline password cracking.
Article 1
2023-10-24
First public PoC for CVE-2013-4786
A proof of concept for exploiting the IPMI vulnerability was released, raising awareness of its risks.
Article 1
2026-07-28
Lava reports on exposed BMCs
Lava researchers identified 36,872 internet-exposed BMCs, with 24,650 leaking password hashes before login.
Article 1
2026-07-28
BleepingComputer coverage
BleepingComputer reported on the risks posed by the exposed BMCs and the potential for widespread exploitation.
BleepingComputer

Community

Browse all →