Researchers found more than 36,000 internet-exposed BMC management interfaces running IPMI, with nearly 25,000 leaking password-derived authentication hashes before login because of CVE-2013-4786 in IPMI v2.0. The exposure affects systems from vendors including HPE and Supermicro, and attackers could use the flaw to crack weak or factory-set passwords offline and gain deep control over servers. #CVE-2013-4786 #IPMI #BMC #HPEiLO #Supermicro #Dell
Keypoints
- More than 36,000 BMC interfaces were found exposed to the internet.
- CVE-2013-4786 allows attackers to extract password hashes before login.
- Offline cracking can recover weak, reused, or factory-set passwords.
- HPE iLO and Supermicro servers were among the affected systems.
- Blocking UDP port 623 and isolating BMC access are recommended defenses.
Read More: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html