Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Powell says student loan system at top of her in-tray

    July 28, 2026

    Did ransomware attacks really decline? Here are your business’ 4 best defenses

    July 28, 2026

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Powell says student loan system at top of her in-tray
    • Did ransomware attacks really decline? Here are your business’ 4 best defenses
    • Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
    • 1inch’s Shared Liquidity Layer Aqua Goes Live
    • Misfolded insulin may be quietly driving diabetes
    • Study investigates how to prevent viral spread from bat guano in Southeast Asia
    • Minnesota teen balances graduation, new roles after dad’s deportation to Laos
    • Led By Donkeys wins compensation over seizure of Gaza protest banner | Led By Donkeys
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Over 24,000 exposed server BMCs leak password hash via decades-old flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.

    For at least a third of them, researchers were able to find the correct password using dictionaries and the patterns on factory stickers for default credentials.

    The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.

    image

    The security issue allows attackers to request an authentication response that can be used to crack the password offline using dedicated GPU rigs or similar setups.

    BMCs and server risks

    BMCs are processors built into a server motherboard that allow administrators to remotely manage the system independent of the operating system. They support low-level actions such as powering servers on/off, updating firmware, or mounting virtual media.

    Access to BMCs can give attackers control over physical servers, letting them change low-level configurations, apply malicious firmware updates, and compromise the system at a layer not monitored by security solutions.

    Researchers at cybersecurity and infrastructure startup Lava say that in real-world settings, recovered credentials may work across multiple management interfaces within the same environment, and that a single compromised BMC could serve as a pivot point to the broader management plane.

    In AI environments with poorly segmented infrastructure, attackers could affect multiple tenants simultaneously.

    “A physical GPU server can support multiple tenants or workloads through virtualization, GPU partitioning, or other sharing mechanisms,” Lava researchers say.

    “In those environments, compromise of one physical server could disrupt or expose several customer workloads.”

    Exploitation diagram
    Exploitation diagram
    Source: Lava

    Massive exposure

    Looking for publicly accessible IPMI services on UDP port 623, the researchers found 36,872 internet-exposed hosts. Of those, 24,650 exposed password-derived authentication material that could be used to perform offline password-cracking attacks.

    According to researchers at Lava, 6,240 of the hosts accepted an empty username during authentication, and subsequent testing confirmed that they were also protected by weak passwords.

    A number of 2,340 instances used weak administrator passwords that matched public dictionaries, making them very easy to breach.

    On a live exposure map seen by BleepingComputer, the United States is at the top of the list with 39% of the vulnerable servers.

    Lava researchers note that a large number of the BMCs it found exposed online are Supermicro systems protected by a 10-character uppercase password printed on the chassis label, with the username ‘ADMIN’ in all instances.

    They argue that while this format theoretically provides ample headroom, its constrained structure still makes offline cracking practical.

    For comparison, the researchers estimated that recovering an HPE factory password would take about 1 day per captured response (an authentication response obtained during the IPMI handshake) on an Apple M3 system.

    BMC interface
    BMC interface
    Source: Lava

    Activity and response

    Lava reports that during its research, it found an internet-exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 BTC.

    While this is not proof of widespread exploitation activity, or even successful attempts, it shows that at least some malicious activity is underway.

    Ransom note on an exposed HPE iLO 4 instance
    Ransom note on an exposed HPE iLO 4 instance
    Source: Lava

    The researchers notified Supermicro in June, and while the company acknowledged the risk, it noted that official guidance for administrators recommends rotating default BMC passwords and isolating management networks.

    The company, though, said it would review stronger default password policies for future hardware revisions.

    Lava also notified HPE but received only a standard auto-response message and no follow-up from the vendor’s security team.

    The researchers recommend keeping IPMI and Redfish off the public internet, rotating factory BMC passwords, restricting access to isolated management networks, and turning off legacy IPMI authentication.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    BMCs decadesold exposed Flaw hash leak password server
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    Why your AI safety certificates are worthless at runtime

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    Hush Security Raises $30 Million for AI Agent Governance

    Google Adopts New Threat Actor Naming System

    Coca-Cola confirms data theft in Fairlife ransomware attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Powell says student loan system at top of her in-tray

    July 28, 2026

    Did ransomware attacks really decline? Here are your business’ 4 best defenses

    July 28, 2026

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    July 28, 2026

    1inch’s Shared Liquidity Layer Aqua Goes Live

    July 28, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Powell says student loan system at top of her in-tray

    July 28, 2026

    Did ransomware attacks really decline? Here are your business’ 4 best defenses

    July 28, 2026

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.