BMCs Stay Crackable Before Login

The management plane is the real blast radius here. A BMC hash leak lets an attacker work offline, so lockouts and host defenses never see the guessing, and a cracked account can still power-cycle servers, mount media, and change firmware even after the OS is rebuilt. Lava now puts the exposed population at 36,872 internet-facing BMCs, with 24,650 returning pre-auth HMAC-SHA1 material tied to CVE-2013-4786. More than 30% of the hashes were recoverable from common wordlists or predictable factory formats, including 2,340 endpoints where names like ADMIN or root matched known passwords. Because this sits in the IPMI 2.0 spec, there is no clean patch path. The operational problem is exposed BMCs with default or factory credentials, especially on Supermicro, HPE, Dell, and similar bare-metal systems.

Part of the PlainSec briefing for 2026-07-28

Sources