CVE Tools
Back to feed
Research Baseboard Management Controller ics-ot-iot IPMI 2.0 Supermicro auth-bypass

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

BleepingComputer·By Bill Toulas··3 min read
CVE Tools coverage

More than 24,000 internet-connected servers are exposing sensitive password hashes due to a long-standing vulnerability in their Baseboard Management Controller (BMC) interface. The flaw, tracked as CVE-2013-4786, affects the IPMI 2.0 protocol and has been present since 2004. Researchers discovered that many of these systems use predictable or weak default credentials, making them highly susceptible to offline brute-force attacks. This issue impacts BMCs from vendors like Supermicro and HPE, which are critical components for remote server management. If exploited, attackers could gain full control over physical hardware, bypassing traditional security layers.