CVE-2013-4786
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100th percentile).
Vulnerabilities & Exploits · Credential Theft
The management plane is the real blast radius here. A BMC hash leak lets an attacker work offline, so lockouts and host defenses never see the guessing, and a cracked account can still power-cycle servers, mount media, and change firmware even after the OS is rebuilt.
Lava now puts the exposed population at 36,872 internet-facing BMCs, with 24,650 returning pre-auth HMAC-SHA1 material tied to CVE-2013-4786. More than 30% of the hashes were recoverable from common wordlists or predictable factory formats, including 2,340 endpoints where names like ADMIN or root matched known passwords.
Because this sits in the IPMI 2.0 spec, there is no clean patch path. The operational problem is exposed BMCs with default or factory credentials, especially on Supermicro, HPE, Dell, and similar bare-metal systems.
7 sources · Aug 4
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100th percentile).
SecurityWeek
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
originalCSO Online
A 13-year-old flaw is exposing tens of thousands of data center management systems
Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system.
originalDark Reading
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
originalPart of the PlainSec briefing for 2026-07-29
Every edition of this story: BMCs Stay Crackable Before Login