CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

24,650 Internet-Exposed BMCs Leak IPMI Password Hashes Before Login

July 28, 2026

Cybersecurity researchers have discovered over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of these, 24,650 were found to disclose password-derived authentication hashes before login due to a vulnerability in the IPMI v2.0 specification, tracked as CVE-2013-4786 (CVSS 7.5). This flaw allows remote attackers to obtain password hashes for valid accounts and conduct offline password guessing attacks.

According to a report from Lava shared with The Hacker News, more than 30% of the returned hashes were associated with passwords that could be recovered using common wordlists and predictable factory chassis-sticker formats. The exposure affected modern Supermicro and HPE servers operated by GPU providers, including systems still using factory-issued passwords. HPE iLO factory passwords were recoverable within a minute using modern GPU hardware, while Supermicro factory passwords were recoverable in approximately one hour.

BMCs are specialized management processors embedded on server motherboards that control power, firmware, remote console access, and system recovery. They run independently of the host operating system via Out-of-Band (OOB) management, making them ideal targets for attackers seeking persistent access. Compromised BMCs can sidestep traditional security controls, survive OS reinstalls, and enable lateral movement in multi-tenant AI data centers.

As of May 6, 2026, a search of the public internet for IPMI services on UDP port 623 uncovered 36,872 unique hosts, with over 14,000 in the U.S. and others in Germany, China, the Netherlands, and the U.K. Threat actors, including ransomware operators, have already been observed targeting exposed BMC interfaces. To mitigate risk, organizations should block UDP port 623 at the network edge, rotate factory passwords, disable legacy IPMI 1.5, restrict BMC access to private management networks, and apply network access controls.

CVEs: CVE-2013-4786, CVE-2026-50522

Malware: iLOBleed

Companies: Lava, HPE, Supermicro, Eclypsium, Dell

Products: HPE iLO, Supermicro BMC