Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 Exposed Servers Leak Passwords via Decades-Old Flaw, Leaving Critical Infrastructure at Risk

A staggering 24,650 servers worldwide have been found to be vulnerable to a well-known security flaw that allows attackers to steal authentication passwords. The issue, which has been lingering for two decades, affects the Baseboard Management Controller (BMC) interface, a critical component of server management systems.

The exposed servers, scattered across various industries and geographic locations, are susceptible to a vulnerability known as CVE-2013-4786. This weakness is rooted in the IPMI 2.0 authentication protocol, introduced in 2004. It allows attackers to request an authentication response that can be used to crack passwords offline using powerful hardware like graphics processing units (GPUs).

BMCs are essentially processors embedded within server motherboards, enabling administrators to manage servers remotely without relying on the operating system. By gaining access to BMCs, attackers can take control of physical servers, modify low-level configurations, and even apply malicious firmware updates. In some cases, a single compromised BMC could serve as a pivot point for further attacks on other management interfaces within the same environment.

In AI environments with poorly segmented infrastructure, an attacker could potentially affect multiple tenants simultaneously. This is particularly concerning in settings where physical servers support multiple workloads through virtualization or partitioning mechanisms. Researchers at Lava, a cybersecurity and infrastructure startup, warn that compromise of one physical server could disrupt or expose several customer workloads.

A massive scan by the researchers revealed 36,872 internet-exposed hosts with IPMI services on UDP port 623. Of these, 24,650 exposed password-derived authentication material that can be used to perform offline password-cracking attacks. Approximately 6,240 hosts accepted an empty username during authentication, and subsequent testing confirmed they were also protected by weak passwords.

A concerning trend emerged from the research: a significant number of vulnerable servers, particularly Supermicro systems, are using default passwords printed on chassis labels, with usernames hardcoded as “ADMIN.” While this format provides some theoretical security benefits, it still makes offline cracking practical. The researchers estimate that recovering an HPE factory password would take around one day per captured response on an Apple M3 system.

The exposed servers are scattered across various industries and locations, with the United States topping the list at 39%. Lava notified Supermicro in June about the vulnerability, but the company acknowledged only that it recommends rotating default BMC passwords and isolating management networks. HPE was also notified, but its security team did not respond.

To mitigate this risk, experts recommend keeping IPMI and Redfish off public networks, rotating factory BMC passwords, restricting access to isolated management networks, and disabling legacy IPMI authentication. By taking proactive measures, organizations can significantly reduce their exposure to this vulnerability and protect critical infrastructure from potential attacks.


Source: Bleeping Computer — 2026-07-28