Nearly 25,000 publicly exposed BMCs are vulnerable through CVE-2013-4786, a 20-year-old flaw that grants attackers direct access to server hardware and potentially the entire management infrastructure.
A two-decade-old IPMI flaw exposes tens of thousands of servers to remote takeover and remains unpatched across many organizations despite public documentation.
Over 24,650 publicly accessible server management interfaces expose IPMI authentication hashes, making them vulnerable to offline attacks on administrative credentials.