PoC public Baseboard Management Controller (BMC) ics-ot-iot BMC info-disclosure
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
CVE Tools coverage
A long-standing vulnerability in Baseboard Management Controllers (BMC) has been found to leave thousands of data centers vulnerable to attacks. The flaw, identified as CVE-2013-4786, was first introduced in 2004 and affects the IPMI 2.0 authentication protocol. Cybersecurity firm Lava reported that nearly 37,000 server-management interfaces on the internet are currently exposed, with over 24,000 leaking password-derived hashes during the authentication process. This weakness allows attackers to extract and crack passwords offline using GPU tools, enabling unauthorized access to highly privileged control systems.