24,650 Internet-Exposed BMCs Leak Password Hashes Without Authentication
A May 6, 2026 internet scan by security firm Lava found 36,872 hosts with IPMI exposed on UDP port 623, of which 24,650 leaked password-derived authentication material to anyone who requested it — no login required. The vulnerability, CVE-2013-4786, is a design flaw in the IPMI v2.0 specification itself, meaning no patch exists and all compliant vendor implementations are affected. Researchers cracked over 30% of the collected hashes offline using common wordlists and predictable factory password formats, with HPE iLO credentials recovered in under a minute. More than 14,000 of the exposed hosts are located in the United States, with further concentration in Germany, China, the Netherlands, and the UK, including servers at GPU and bare-metal cloud providers. Recommended mitigations include blocking UDP port 623 at the network edge, isolating BMCs on a dedicated management VLAN, disabling IPMI 1.5, and replacing all factory-issued credentials immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in