Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes because of CVE-2013-4786, an old IPMI 2.0 flaw in Baseboard Management Controller interfaces. Researchers also found evidence of weak factory and dictionary-based credentials, and an exposed HPE iLO 4 page showing a ransom note, suggesting active abuse of these systems. #CVE-2013-4786 #IPMI #BMC #Supermicro #HPEiLO4

Keypoints

  • More than 24,000 internet-exposed servers are leaking authentication hashes through CVE-2013-4786.
  • The flaw affects IPMI 2.0 and allows offline password cracking from captured authentication responses.
  • Researchers found many weak credentials, including factory defaults and passwords matching public dictionaries.
  • Supermicro systems and HPE iLO 4 instances were among the exposed targets.
  • Experts recommend removing IPMI and Redfish from the public internet and isolating management networks.

Read More: https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/