Find notable cyber news and cases, enriched with sources, timelines, and signals.

BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)

Vulnerability
First reported
Last updated
Happening score
H score 68
3 unique sources, 3 articles

Summary

Hide ▲

24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane credentials. Researchers found 36,872 publicly reachable IPMI services on UDP port 623, and at least a third of the exposed systems yielded the correct password after dictionary and factory-sticker pattern testing. Compromised BMC access can bypass operating-system monitoring, alter low-level settings, update firmware, and pivot into the wider management plane. The current response is mitigation-focused, with guidance to rotate default passwords, isolate management networks, and keep IPMI and Redfish off the public internet.

Related Happenings

Internet-exposed BMC password-hash exposure

Data Leak
H score76 First: 28.07.2026 15:10 Last: 28.07.2026 15:10 Sources 1

How related: Of them, 24,650 returned password-derived authentication material, which attackers could leverage for offline password-cracking attacks.

About this happening: Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane...

TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools

Malware Activity
H score36 First: 30.06.2026 18:34 Last: 30.06.2026 18:34 Sources 1

About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...

CISA Emergency Directive 26-03 for Cisco SD-WAN

Public Sector Action
H score34 First: 25.02.2026 14:00 Last: 25.02.2026 14:00 Sources 1

About this happening: CISA issued Emergency Directive 26-03 and supplemental guidance to force immediate remediation of Cisco SD-WAN vulnerabilities across Federal Civilian Executive Bran...

CISA KEV patch order for Dell RecoverPoint

Public Sector Action
H score36 First: 19.02.2026 17:30 Last: 19.02.2026 17:30 Sources 1

About this happening: CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...

UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign

Campaign
H score44 First: 17.02.2026 22:15 Last: 17.02.2026 22:15 Sources 1

About this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...

Latest development: 19.02.2026 17:30

CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.

Timeline

  1. 28.07.2026 15:10 4 articles · 14d ago

    Researchers find 24,650 exposed BMC/IPMI hosts leaking password hashes via CVE-2013-4786

    Initial Disclosure

    Researchers report that more than 24,000 internet-exposed server BMCs are leaking authentication password hashes through CVE-2013-4786, an IPMI 2.0 authentication weakness. Their scan found 36,872 publicly reachable IPMI services on UDP port 623, with 24,650 returning password-derived authentication material that could be cracked offline; in 6,240 cases the host accepted an empty username, 2,340 instances used weak administrator passwords, and many exposed Supermicro systems relied on a 10-character uppercase chassis-label password with the username ‘ADMIN’. The researchers also say an HPE factory password could take about 1 day per captured response to recover on an Apple M3 system, and they recommend rotating factory BMC passwords, isolating management networks, and keeping IPMI and Redfish off the public internet.

    Show sources