Find notable cyber news and cases, enriched with sources, timelines, and signals.

Internet-exposed BMC password-hash exposure

Data Leak
First reported
Last updated
Happening score
H score 76
1 unique sources, 1 articles

Summary

Hide ▲

Internet-exposed server BMCs are leaking password-derived authentication material at scale, creating a risk of offline password cracking and unauthorized management-plane access. 24,650 hosts returned recoverable responses tied to IPMI services on UDP port 623.

Related Happenings

BMC/IPMI offline-crackable authentication security flaw (CVE-2013-4786)

Vulnerability
H score70 First: 28.07.2026 15:10 Last: 28.07.2026 15:10 Sources 1

How related: The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.

About this happening: 24,650 internet-exposed BMC/IPMI hosts are leaking password-derived authentication material through CVE-2013-4786, creating offline-cracking risk for management-plane...

Timeline

  1. 28.07.2026 15:10 2 articles · 1h ago

    Lava finds more than 24,000 exposed BMCs leaking password hashes

    Initial Disclosure

    Lava says more than 24,000 internet-exposed server BMCs are leaking password hashes through CVE-2013-4786, an IPMI 2.0 authentication weakness, and that 24,650 exposed hosts returned password-derived authentication material suitable for offline cracking. The researchers also identified 6,240 cases that accepted an empty username, 2,340 weak administrator passwords matching public dictionaries, and many exposed Supermicro systems using a 10-character uppercase chassis-label password with the username ‘ADMIN’.

    Show sources