Internet-exposed BMC password-hash exposure
Data Leak
Summary
Hide ▲
Show ▼
Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane access. 24,650 hosts returned recoverable responses tied to IPMI services on UDP port 623.
Related Happenings
BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)
Vulnerability
H score70
First: 28.07.2026 15:10
Last: 28.07.2026 15:10
Sources 1
How related:
The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.
About this happening:
24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane...
BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)
VulnerabilityHow related: The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.
About this happening: 24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane...
Timeline
-
28.07.2026 15:10 2 articles · 1h ago
Lava finds more than 24,000 exposed BMCs leaking password hashes
Initial DisclosureLava says more than 24,000 internet-exposed server BMCs are leaking password hashes through CVE-2013-4786, an IPMI 2.0 authentication weakness, and that 24,650 exposed hosts returned password-derived authentication material suitable for offline cracking. The researchers also identified 6,240 cases that accepted an empty username, 2,340 weak administrator passwords matching public dictionaries, and many exposed Supermicro systems using a 10-character uppercase chassis-label password with the username ‘ADMIN’.
Show sources
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw — www.bleepingcomputer.com — 28.07.2026 15:10
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw — www.bleepingcomputer.com — 28.07.2026 15:10