Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 servers exposed to decades-old password cracking vulnerability

A staggering number of internet-exposed servers are vulnerable to a 20-year-old security flaw that allows attackers to crack passwords offline using specialized equipment. Researchers at Lava discovered that more than 24,000 servers are leaking authentication password hashes due to the weakness in their Baseboard Management Controller (BMC) interface.

These BMCs are processors built into server motherboards that allow administrators to remotely manage systems without accessing the operating system. However, access to these controllers can give attackers control over physical servers, enabling them to change low-level configurations, apply malicious firmware updates, and compromise sensitive data at a layer not monitored by security solutions.

The vulnerability, known as CVE-2013-4786, is rooted in IPMI 2.0 authentication protocol, which was introduced in 2004. It allows attackers to request an authentication response that can be used to crack passwords offline using dedicated GPU rigs or similar setups. In a worrying trend, researchers found that for at least a third of the exposed servers, they were able to recover the correct password using dictionaries and patterns on factory stickers for default credentials.

The United States is disproportionately affected by this issue, with 39% of the vulnerable servers located there. A significant number of these BMCs are Supermicro systems protected by a weak password format printed on the chassis label. While this format theoretically provides ample headroom, its constrained structure makes offline cracking practical.

Researchers warn that recovered credentials may work across multiple management interfaces within the same environment, and that a single compromised BMC could serve as a pivot point to the broader management plane. In AI environments with poorly segmented infrastructure, attackers could affect multiple tenants simultaneously. This highlights the importance of segmenting infrastructure, rotating default passwords, and restricting access to isolated management networks.

While Supermicro acknowledged the risk and recommended guidance for administrators, it has not yet implemented stronger default password policies for future hardware revisions. HPE, on the other hand, failed to respond to Lava’s notification, sending only a standard auto-response message.

To mitigate this risk, security teams should keep IPMI and Redfish off the public internet, rotate factory BMC passwords, restrict access to isolated management networks, and turn off legacy IPMI authentication. This issue serves as a reminder that even decades-old vulnerabilities can have significant consequences if left unaddressed. As researchers warn, “test every layer before attackers do.”


Source: Bleeping Computer — 2026-07-28