Thousands of internet-exposed server management interfaces can still leak password-derived data that attackers can crack offline, giving them a path into highly privileged server controls. Security firm Lava says more than 24,000 exposed Baseboard Management Controller (BMC) interfaces disclose authentication hashes before login through the long-known IPMI flaw CVE-2013-4786, and found thousands also using weak, default, or predictable passwords. The affected surface is UDP port 623 on IPMI 2.0 implementations, where a Remote Authenticated Key-Exchange Protocol (RAKP) response exposes an HMAC that can be attacked offline.
Why it matters: Organizations with internet-reachable BMC or IPMI management ports may be giving attackers a quiet route to full server-management access, including power control and firmware changes. This is urgent for data center and enterprise operators: remove BMCs from the public internet, restrict management access, audit for weak or factory passwords, and disable or segment IPMI where possible.
Ionut Arghire
2026.08.04
100% relevant
This article establishes a distinct infrastructure-exposure story by tying CVE-2013-4786 to current internet-scale BMC/IPMI exposure and quantifying thousands of reachable systems with crackable authentication material and weak credentials.
← Back to all stories