Find notable cyber news and cases, enriched with sources, timelines, and signals.

BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)

Vulnerability
First reported
Last updated
Happening score
H score 70
1 unique sources, 1 articles

Summary

Hide ▲

24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane credentials. Researchers found 36,872 publicly reachable IPMI services on UDP port 623, and at least a third of the exposed systems yielded the correct password after dictionary and factory-sticker pattern testing. Compromised BMC access can bypass operating-system monitoring, alter low-level settings, update firmware, and pivot into the wider management plane. The current response is mitigation-focused, with guidance to rotate default passwords, isolate management networks, and keep IPMI and Redfish off the public internet.

Related Happenings

Internet-exposed BMC password-hash exposure

Data Leak
H score76 First: 28.07.2026 15:10 Last: 28.07.2026 15:10 Sources 1

How related: Of them, 24,650 returned password-derived authentication material, which attackers could leverage for offline password-cracking attacks.

About this happening: Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane...

Timeline

  1. 28.07.2026 15:10 2 articles · 1h ago

    Researchers find 24,650 exposed BMC/IPMI hosts leaking password hashes via CVE-2013-4786

    Initial Disclosure

    Researchers report that more than 24,000 internet-exposed server BMCs are leaking authentication password hashes through CVE-2013-4786, an IPMI 2.0 authentication weakness. Their scan found 36,872 publicly reachable IPMI services on UDP port 623, with 24,650 returning password-derived authentication material that could be cracked offline; in 6,240 cases the host accepted an empty username, 2,340 instances used weak administrator passwords, and many exposed Supermicro systems relied on a 10-character uppercase chassis-label password with the username ‘ADMIN’. The researchers also say an HPE factory password could take about 1 day per captured response to recover on an Apple M3 system, and they recommend rotating factory BMC passwords, isolating management networks, and keeping IPMI and Redfish off the public internet.

    Show sources