Skip to content
Over 24,000 Servers Expose Password Hashes via BMC Vulnerability

Over 24,000 Servers Expose Password Hashes via BMC Vulnerability

First seen 28 Jul 2026, 15:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 13:48 UTC
  • Over 24,000 servers are leaking password hashes due to a 20-year-old BMC vulnerability.
  • CVE-2013-4786 allows attackers to exploit weak authentication in IPMI 2.0.
  • Compromised BMCs can enable extensive control over servers, bypassing typical security measures.

A significant vulnerability in Baseboard Management Controllers (BMCs) has been identified, exposing over 24,000 servers to the internet. This exposure is due to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol, allowing attackers to retrieve password hashes before login. Researchers from Lava found that 36,872 BMC interfaces were publicly accessible, with 24,650 leaking authentication hashes that could be cracked offline. Many of these servers, particularly from Supermicro and HPE, are still using weak or default passwords, making them easy targets. The compromised BMCs can provide attackers with extensive control over the servers, enabling them to execute malicious actions beneath the visibility of traditional security measures. The issue is exacerbated in environments with poor segmentation, potentially affecting multiple tenants simultaneously. Immediate action is recommended to secure these vulnerable systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2013-07-08
CVE-2013-4786 published
The vulnerability in the IPMI 2.0 authentication protocol was officially documented.
NVD
2023-10-24
First public PoC released
A proof of concept for exploiting CVE-2013-4786 was made public, increasing awareness of the vulnerability.
NVD
2026-07-28
Lava researchers report BMC exposure
Lava identified 36,872 internet-exposed BMCs, with 24,650 leaking password hashes due to CVE-2013-4786.
lavahq.io
2026-07-28
BleepingComputer reports on BMC vulnerabilities
BleepingComputer confirmed that over 24,000 servers are vulnerable due to weak passwords and the IPMI flaw.
Bleepingcomputer

More articles in this cluster (13)

Following this threat?

Track HPE and CVE-2013-4786 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed