Cybersecurity researchers have identified over 24,000 internet-exposed servers that are vulnerable to a 20-year-old flaw, CVE-2013-4786. This vulnerability, rooted in the Intelligent Platform Management Interface (IPMI) v2.0 specification, allows these servers to leak authentication password hashes before login.
The findings indicate that out of nearly 37,000 internet-exposed server-management interfaces running the IPMI protocol, 24,650 disclose password-derived authentication hashes. This issue enables remote attackers to obtain these hashes and perform offline password guessing attacks.
CVE-2013-4786 is an information disclosure flaw with a CVSS score of 7.5. It allows attackers to request an authentication response that contains the HMAC from an RMCP+ Authenticated Key-Exchange Protocol (RAKP) message, which can then be used to crack the password offline using dedicated GPU rigs or similar setups.
Dell has noted that this is an inherent problem with the IPMI v2.0 specification itself, meaning there is no direct patch available for the vulnerability. The protocol was introduced in 2004.
Baseboard Management Controllers (BMCs) are processors embedded in server motherboards that enable remote management of the system, independent of the operating system. They provide 'lights out' and 'out-of-band' management capabilities, allowing administrators to perform tasks such as powering servers on/off, updating firmware, and making low-level configuration changes, even when the server's operating system is unresponsive.
Access to BMCs grants attackers control over physical servers, enabling them to alter low-level configurations, apply malicious firmware updates, and compromise the system at a layer often not monitored by security solutions. In many implementations, credentials for IPMI may also work for web interfaces or Redfish APIs, further expanding the potential impact of a compromise.
Researchers found that for at least one-third of the exposed servers, they could recover the correct password using dictionaries and patterns from factory stickers for default credentials. More than 30% of the returned hashes were associated with passwords recoverable using common wordlists and predictable factory chassis-sticker formats.
This vulnerability poses a significant risk to server infrastructure, including modern AI data centers, as it can lead to deep and persistent access for attackers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Research presented at Black Hat revealed critical vulnerabilities, some over a decade old, in Baseboard Management Controllers (BMCs) from major manufacturers like HPE, Supermicro, and Dell. These flaws allow remote attackers to backdoor thousands of internet-connected servers, providing deep and persistent access to data centers. The persistence of these vulnerabilities highlights a significant, unaddressed security risk in enterprise server infrastructure.
A 22-year-old vulnerability in Baseboard Management Controller (BMC) management processors, CVE-2013-4786, is exposing thousands of data centers to potential compromise, according to security firm Lava. This flaw allows attackers to obtain password hashes from IPMI 2.0 authentication, enabling offline cracking and unauthorized access to critical server management functions.
Cybersecurity researchers found over 24,000 internet-exposed Baseboard Management Controllers (BMCs) that disclose password hashes before login due to a vulnerability in the IPMI v2.0 specification. This flaw, CVE-2013-4786, allows remote attackers to obtain password hashes and conduct offline password guessing attacks, posing a risk to server infrastructure, including modern AI data centers.
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability (CVE-2013-4786) in their Baseboard Management Controller (BMC) interface. This vulnerability allows attackers to crack passwords offline, potentially leading to full control over physical servers and broader management plane compromise, especially in poorly segmented AI environments.