BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)
Vulnerability
Summary
Hide ▲
Show ▼
24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane credentials. Researchers found 36,872 publicly reachable IPMI services on UDP port 623, and at least a third of the exposed systems yielded the correct password after dictionary and factory-sticker pattern testing. Compromised BMC access can bypass operating-system monitoring, alter low-level settings, update firmware, and pivot into the wider management plane. The current response is mitigation-focused, with guidance to rotate default passwords, isolate management networks, and keep IPMI and Redfish off the public internet.
Related Happenings
Internet-exposed BMC password-hash exposure
Data Leak
H score76
First: 28.07.2026 15:10
Last: 28.07.2026 15:10
Sources 1
How related:
Of them, 24,650 returned password-derived authentication material, which attackers could leverage for offline password-cracking attacks.
About this happening:
Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane...
Internet-exposed BMC password-hash exposure
Data LeakHow related: Of them, 24,650 returned password-derived authentication material, which attackers could leverage for offline password-cracking attacks.
About this happening: Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane...
Timeline
-
28.07.2026 15:10 2 articles · 1h ago
Researchers find 24,650 exposed BMC/IPMI hosts leaking password hashes via CVE-2013-4786
Initial DisclosureResearchers report that more than 24,000 internet-exposed server BMCs are leaking authentication password hashes through CVE-2013-4786, an IPMI 2.0 authentication weakness. Their scan found 36,872 publicly reachable IPMI services on UDP port 623, with 24,650 returning password-derived authentication material that could be cracked offline; in 6,240 cases the host accepted an empty username, 2,340 instances used weak administrator passwords, and many exposed Supermicro systems relied on a 10-character uppercase chassis-label password with the username ‘ADMIN’. The researchers also say an HPE factory password could take about 1 day per captured response to recover on an Apple M3 system, and they recommend rotating factory BMC passwords, isolating management networks, and keeping IPMI and Redfish off the public internet.
Show sources
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw — www.bleepingcomputer.com — 28.07.2026 15:10
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw — www.bleepingcomputer.com — 28.07.2026 15:10