Skip to content

13-Year-Old BMC Vulnerability Exposes Tens of Thousands of Data Centers

Bottom line: BMCs on over 36,000 servers are accessible to attackers via CVE-2013-4786, allowing them to gain control of critical infrastructure below OS-level protection.

An authentication flaw in Baseboard Management Controllers published in 2013 enables attackers undetected access below the operating system. Lava security researchers found 36,872 internet-accessible BMCs, two-thirds of which disclosed authentication hashes.

Baseboard Management Controllers (BMCs) are specialized microcontrollers on server motherboards that operate independently of the main processor, memory and operating system. They provide administrators out-of-band management, firmware updates, configuration changes and hardware sensor readings – without physical access. BMCs thus represent one of the most privileged control points in data centers.

Lava researchers demonstrated that BMCs on Supermicro and HPE servers can be compromised in minutes by exploiting CVE-2013-4786. The vulnerability affects the IPMI 2.0 authentication protocol. Of 36,872 publicly accessible BMCs, 66 percent (24,650) disclosed authentication hashes. The researchers tested these hashes against standard wordlists and found over 30 percent featured “reused, factory-set or predictably formatted” passwords – cracked on average within minutes on the first run. Additionally, nearly 17 percent accepted an empty username field with weak passwords.

Supermicro devices represented over half of all responding BMCs, however their passwords were not found in wordlists – a result of the 2019 transition to individual, factory-assigned passwords of ten capital letters on the chassis label. Supermicro announced improvements to future hardware revisions and has since remediated the exposure.

The risk is significant because BMCs operate on shared out-of-band management networks with frequently reused administrative credentials. Changes to BMCs or platform hardware persist across OS reinstalls, disk replacements and standard incident response procedures. For CISOs, this means conventional security tools that monitor the OS, kernel, containers and workloads do not capture this attack surface.


Source: www.csoonline.com · Published 29 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: