Research Baseboard Management Controller ics-ot-iot IPMI 2.0 Supermicro auth-bypass
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
CVE Tools coverage
More than 24,000 internet-connected servers are exposing sensitive password hashes due to a long-standing vulnerability in their Baseboard Management Controller (BMC) interface. The flaw, tracked as CVE-2013-4786, affects the IPMI 2.0 protocol and has been present since 2004. Researchers discovered that many of these systems use predictable or weak default credentials, making them highly susceptible to offline brute-force attacks. This issue impacts BMCs from vendors like Supermicro and HPE, which are critical components for remote server management. If exploited, attackers could gain full control over physical hardware, bypassing traditional security layers.