Research IPMI 2.0 ics-ot-iot BMC Supermicro auth-bypass
Exposed BMCs hand out password hashes before login
CVE Tools coverage
A vulnerability in IPMI 2.0 allows attackers to retrieve password hashes from a server's BMC without authenticating, simply by sending a request to UDP port 623. This flaw, identified as CVE-2013-4786, affects BMCs from vendors like Supermicro and HPE. Researchers found that nearly two-thirds of exposed BMCs leaked authentication material, enabling offline brute-force attacks. Default factory passwords used on many devices are also vulnerable to rapid cracking using modern GPU setups. Lava researchers recommend blocking UDP port 623 at the network perimeter and replacing default credentials to mitigate risk.