top of page
perceptive_background_267k.jpg

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Published:

28 July 2026 at 12:10:23

Alert date:

28 July 2026 at 13:00:52

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure, Identity & Access

Over 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interfaces. The flaw affects the IPMI (Intelligent Platform Management Interface) protocol, which is used for out-of-band server management. Despite being a decades-old known issue, thousands of BMCs remain publicly accessible on the internet and are actively leaking credentials. Password hashes exposed in this manner can be cracked offline, potentially giving attackers full administrative control over affected servers. The vulnerability represents a significant risk to enterprise and data center environments where BMC access is inadvertently exposed to the public internet. Organizations are advised to restrict BMC/IPMI access to isolated management networks and avoid direct internet exposure.

Technical details

CVE-2013-4786 is a 20-year-old IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004. The vulnerability allows attackers to request an authentication response (captured during the IPMI handshake) that can then be used to crack the password offline using GPU rigs or similar setups. Researchers at Lava scanned for publicly accessible IPMI services on UDP port 623 and found 36,872 internet-exposed hosts. Of those, 24,650 exposed password-derived authentication material usable for offline password cracking. Additionally, 6,240 hosts accepted an empty username during authentication and were found to use weak passwords. A further 2,340 instances used weak administrator passwords matching public dictionaries. The United States accounts for 39% of vulnerable servers. Many exposed BMCs are Supermicro systems using a 10-character uppercase default password printed on the chassis label with the username 'ADMIN'. Researchers estimated recovering an HPE factory password would take approximately 1 day per captured response on an Apple M3 system. At least one internet-exposed HPE iLO 4 login page was found displaying a ransom note demanding 0.3 BTC, indicating active exploitation. In AI environments with poorly segmented infrastructure, compromise of one physical server could affect multiple tenants through virtualization, GPU partitioning, or other sharing mechanisms.

Mitigation steps:

1. Keep IPMI and Redfish interfaces off the public internet. 2. Rotate all factory/default BMC passwords immediately. 3. Restrict BMC/IPMI access to isolated, dedicated management networks not reachable from the internet. 4. Disable legacy IPMI authentication where possible. 5. Audit all internet-exposed hosts on UDP port 623 and remove public exposure. 6. Ensure strong, unique passwords are set for all BMC interfaces, avoiding default credentials. 7. Implement network segmentation to prevent a compromised BMC from serving as a pivot point to the broader management plane. 8. For Supermicro systems, replace default 'ADMIN' credentials and chassis-label passwords with strong, unique alternatives. 9. Monitor for unauthorized authentication attempts against BMC interfaces.

Affected products:

Supermicro BMC (Baseboard Management Controller) systems
HPE iLO 4
Any server implementing IPMI 2.0 protocol

Related links:

Related CVE's:

Related threat actors:

IOC's:

UDP port 623 (IPMI service exposure), Ransom note on HPE iLO 4 login page demanding 0.3 BTC

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page