Nearly 25,000 publicly exposed BMCs are vulnerable through CVE-2013-4786, a 20-year-old flaw that grants attackers direct access to server hardware and potentially the entire management infrastructure.
BMCs on over 36,000 servers are accessible to attackers via CVE-2013-4786, allowing them to gain control of critical infrastructure below OS-level protection.