Vulnerabilities · 41 days ago
BMCs Stay Crackable Before Login The management plane is the real blast radius here. A BMC hash leak lets an attacker work offline, so lockouts and host defenses never see the guessing, and a cracked account can still power-cycle servers, mount media, and change firmware even after the OS is rebuilt.
Lava now puts the exposed population at 36,872 internet-facing BMCs, with 24,650 returning pre-auth HMAC-SHA1 material tied to CVE-2013-4786 . More than 30% of the hashes were recoverable from common wordlists or predictable factory formats, including 2,340 endpoints where names like ADMIN or root matched known passwords.
Because this sits in the IPMI 2.0 spec, there is no clean patch path. The operational problem is exposed BMCs with default or factory credentials, especially on Supermicro, HPE, Dell, and similar bare-metal systems.
NVD KEV
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100th percentile).
Timeline Sources 7 sources covering this story
SecurityWeek Aug 4
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
CSO Online Jul 28
A 13-year-old flaw is exposing tens of thousands of data center management systems
Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system.
Dark Reading Jul 28
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
The Hacker News Jul 28
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.
Wiz Research Jul 28
The Security Risks Hiding Behind Exposed MCP Servers | Wiz Blog
Wiz Research reveals how unauthenticated MCP servers expose sensitive cloud databases, IAM, and internal tools to internet callers—and how to fix it.
Help Net Security Jul 28
Exposed BMCs hand out password hashes before login - Help Net Security
An exposed BMC IPMI vulnerability let 24,650 servers hand out password hashes before login.
BleepingComputer Jul 28
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Entities Part of the PlainSec briefing for 2026-08-04
Editions Related stories
Vulnerabilities · 41 days ago
BMCs Stay Crackable Before Login The management plane is the real blast radius here. A BMC hash leak lets an attacker work offline, so lockouts and host defenses never see the guessing, and a cracked account can still power-cycle servers, mount media, and change firmware even after the OS is rebuilt.
Lava now puts the exposed population at 36,872 internet-facing BMCs, with 24,650 returning pre-auth HMAC-SHA1 material tied to CVE-2013-4786 . More than 30% of the hashes were recoverable from common wordlists or predictable factory formats, including 2,340 endpoints where names like ADMIN or root matched known passwords.
Because this sits in the IPMI 2.0 spec, there is no clean patch path. The operational problem is exposed BMCs with default or factory credentials, especially on Supermicro, HPE, Dell, and similar bare-metal systems.
NVD KEV
CVSS 7.5 HIGH: the IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows… EPSS 79% (100th percentile).
Timeline Sources 7 sources covering this story
SecurityWeek Aug 4
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
CSO Online Jul 28
A 13-year-old flaw is exposing tens of thousands of data center management systems
Lava researchers found more than 36,000 internet-exposed baseboard management controllers vulnerable to a 13-year-old IPMI flaw, giving attackers a path beneath the operating system.
Dark Reading Jul 28
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
The Hacker News Jul 28
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.
Wiz Research Jul 28
The Security Risks Hiding Behind Exposed MCP Servers | Wiz Blog
Wiz Research reveals how unauthenticated MCP servers expose sensitive cloud databases, IAM, and internal tools to internet callers—and how to fix it.
Help Net Security Jul 28
Exposed BMCs hand out password hashes before login - Help Net Security
An exposed BMC IPMI vulnerability let 24,650 servers hand out password hashes before login.
BleepingComputer Jul 28
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Entities Part of the PlainSec briefing for 2026-08-04
Editions Related stories