CVE Tools

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

BleepingComputerBy Bill Toulas

ResearchBaseboard Management ControllerIPMI 2.0

Our summary

More than 24,000 internet-connected servers are exposing sensitive password hashes due to a long-standing vulnerability in their Baseboard Management Controller (BMC) interface. The flaw, tracked as CVE-2013-4786, affects the IPMI 2.0 protocol and has been present since 2004. Researchers discovered that many of these systems use predictable or weak default credentials, making them highly susceptible to offline brute-force attacks. This issue impacts BMCs from vendors like Supermicro and HPE, which are critical components for remote server management. If exploited, attackers could gain full control over physical hardware, bypassing traditional security layers.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store