Close Menu
NCIJ Network NCIJ Network
    What's Hot

    As France burns, the far right sees an opening – POLITICO

    July 29, 2026

    Burnham invites Tories and Lib Dems to talks about social care

    July 29, 2026

    Senate Confirms Jay Clayton to Lead U.S. Intelligence Community

    July 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • As France burns, the far right sees an opening – POLITICO
    • Burnham invites Tories and Lib Dems to talks about social care
    • Senate Confirms Jay Clayton to Lead U.S. Intelligence Community
    • Japan’s Takaichi warns of ‘race against time’ to rescue earthquake survivors
    • The US is banning foreign robots
    • Fortinet’s new FortiGate platform converges firewall, SASE technologies
    • European Institutions Launch RL1 Blockchain Network
    • Trump ICE detention policy divides Wisconsin federal judges
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, July 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 29, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.

    Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to a vulnerability with the IPMI v2.0 specification itself, according to a new report Lava shared with The Hacker News. IPMI v2.0 was introduced in February 2024.

    The issue in question is CVE-2013-4786 (CVSS score: 7.5), a high-severity information disclosure flaw that enables remote attackers to obtain password hashes for valid accounts and conduct offline password guessing attacks by obtaining the HMAC from an RMCP+ Authenticated Key-Exchange Protocol (RAKP) message response from a BMC.

    Per an advisory released by Dell, “this is an inherent problem with the specification for IPMI v2.0,” with the PC maker noting that there is no patch.

    “More than 30% of the returned hashes were associated with passwords that could be recovered using common wordlists and predictable factory chassis-sticker formats,” security researcher Michael Katchinskiy said. “The exposure also affected modern Supermicro and HPE servers operated by GPU providers, including systems that were still using factory-issued passwords.”

    Cybersecurity

    BMCs are specialized management processors embedded on a server’s motherboard that control power, firmware, remote console access, operating system installation, and system recovery. They also act as a crucial component for remote data center automation and uptime to monitor hardware telemetry and facilitate mass deployment of firmware updates and BIOS configurations.

    To bridge remote commands to the hardware, the BMC typically communicates using protocols like IPMI and Redfish. As highlighted by firmware security company Eclypsium in late 2022 and early 2023, the privileged position enjoyed by BMCs can also make them ideal attack targets for bad actors looking to gain remote control and deploy persistent malware.

    Because BMCs run completely independently of the host operating system, a mechanism known as Out-of-Band (OOB) management, an attacker who manages to successfully compromise an exposed BMC can sidestep traditional security controls, survive operating system reinstalls, and maintain access.

    “In modern AI data centers, where the same bare-metal environment often hosts multiple tenants, a single exposed BMC can potentially place multiple organizations’ workloads at risk through shared infrastructure or lateral movement, making this a significant blind spot in the infrastructure underpinning the AI data center boom,” the Israeli company said.

    At the heart of the research is CVE-2013-4786, a 20-year-old weakness in IPMI 2.0, which an attacker can exploit to recover weak, reused, factory-set, or predictably formatted passwords.

    “During the authentication process, the BMC can return a message response containing an HMAC-SHA1 authentication code calculated using the account password and session values known to the requester,” Katchinskiy explained. “An unauthenticated remote party that can reach UDP port 623 can request this response and test password guesses offline. Unlike repeated online login attempts, the offline process does not require a new request to the BMC for every password candidate.”

    As of May 6, 2026, a search of the public internet for IPMI services exposed on UDP port 623 uncovered 36,872 unique hosts, of which more than 14,000 are located in the U.S. The remaining systems are concentrated in Germany, China, the Netherlands, and the U.K.

    Further analysis has determined that nearly 25,000 exposed password-derived authentication materials before login, allowing offline credential cracking. Perhaps even more concerningly, a total of 6,240 BMCs returned authentication material for an empty username that matched a weak password candidate and another 2,340 BMCs returned authentication data for a named account such as ADMIN or root that matched a password from publicly available wordlists.

    Cybersecurity

    In tests conducted by Lava, HPE iLO factory passwords were recoverable within a minute using modern GPU hardware, while Supermicro factory passwords were recoverable in approximately one hour despite being uniquely assigned to each server. In response to the findings, Supermicro said it will evaluate possible improvements to the default password policy for future hardware revisions.

    “CVE-2013-4786 is not new, but the risk around it has changed,” Lava said. GPU cracking has made offline password recovery faster, while modern AI and bare-metal environments have made each exposed server more valuable.

    On top of that, evidence has emerged that threat actors are already targeting internet-exposed BMC interfaces, including ransomware operators leaving an extortion note on an HPE iLO 4 login page. It’s not clear who is behind the activity. That said, HPE iLO servers have been singled out as far back as 2020 to deploy a rootkit called iLOBleed.

    To counter the risk, it’s advised to block UDP port 623 at the network edge, rotate factory-issued passwords during provisioning, disable legacy or weak options such as IPMI 1.5, restrict BMC access to a dedicated private management network, and apply network access controls to ensure only approved administrative systems can reach BMC interfaces.

    “Organizations have spent years hardening cloud workloads and operating systems, but many have overlooked the infrastructure that sits beneath them,” said Yakir Kadkoda, CTO and co-founder at Lava, in a statement.

    “These management controllers hold the keys to servers and data centers. Once compromised, attackers can operate below the visibility of almost any security tools, maintain persistence even after systems are rebuilt, and potentially move deeper into critical infrastructure. As AI infrastructure rapidly expands, securing this layer has become far more urgent.”

    BMCs Disclose Hashes InternetExposed IPMI Login password
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fortinet’s new FortiGate platform converges firewall, SASE technologies

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    When AI Agents Escape Sandboxes, Old Security Rules Apply

    CubePilot drone software dev hit by DNS hijacking to intercept traffic

    Flaw From 2002 Exposes Data Centers to Server Takeover

    Samsung’s AI-powered glasses could be looking at your data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    As France burns, the far right sees an opening – POLITICO

    July 29, 2026

    Burnham invites Tories and Lib Dems to talks about social care

    July 29, 2026

    Senate Confirms Jay Clayton to Lead U.S. Intelligence Community

    July 29, 2026

    Japan’s Takaichi warns of ‘race against time’ to rescue earthquake survivors

    July 29, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    As France burns, the far right sees an opening – POLITICO

    July 29, 2026

    Burnham invites Tories and Lib Dems to talks about social care

    July 29, 2026

    Senate Confirms Jay Clayton to Lead U.S. Intelligence Community

    July 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.