In a nutshell: Nearly 25,000 publicly exposed BMCs are vulnerable through CVE-2013-4786, a 20-year-old flaw that grants attackers direct access to server hardware and potentially the entire management infrastructure.
More than 24,000 publicly accessible Baseboard Management Controllers (BMCs) are leaking authentication hashes that can be cracked offline to recover passwords. The cause is CVE-2013-4786, a known weakness in the IPMI-2.0 protocol that has not been widely patched since its discovery nearly 20 years ago.
Security firm Lava identified 36,872 IPMI services accessible via UDP port 623 in its analysis. From these, 24,650 systems exposed authentication material that can be used for offline password attacks via GPU systems. 6,240 systems accepted empty usernames with weak passwords, and another 2,340 instances used passwords found in public dictionaries. The geographic distribution shows the USA accounting for 39 percent of vulnerable servers.
A large portion of affected systems are from Supermicro and use a factory-set password format of a ten-digit uppercase string printed on the chassis with the identical username ADMIN. This standard format makes offline cracking practical, even though it theoretically offers sufficient entropy. HPE systems are estimated by researchers to require approximately one day of computation time per intercepted authentication response to recover the factory-set password.
The CVE-2013-4786 vulnerability in the IPMI-2.0 protocol (introduced in 2004) allows attackers to intercept authentication responses and attack them offline. A compromised BMC provides direct access to low-level configurations of the physical server, enables firmware updates, and bypasses traditional security solutions. According to Lava researchers’ experience, the recovered credentials frequently work for other management interfaces in the same infrastructure.
The situation is particularly critical in AI environments with insufficient segmentation, where a single compromised GPU server can simultaneously support multiple tenant workloads through virtualization or GPU partitioning. A compromise could expose or disrupt multiple customer workloads. During the investigation, researchers also discovered a publicly accessible HPE iLO-4 login page with an extortion notice demanding payment of 0.3 Bitcoin.
Source: www.it-daily.net · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.