24,000 Internet-Exposed Servers Leak Password Hashes Due to 20-Year-Old BMC Vulnerability
Researchers at cybersecurity firm Lava have identified over 24,650 internet-exposed servers leaking authentication password hashes due to a two-decade-old vulnerability (CVE-2013-4786) in their Baseboard Management Controller (BMC) interfaces. The flaw, rooted in the IPMI 2.0 protocol introduced in 2004, allows attackers to capture authentication responses and crack passwords offline using GPU rigs or similar tools.
BMCs enable remote server management including power control, firmware updates, and virtual media mounting making them high-value targets. Compromised BMCs grant attackers deep system access, bypassing traditional security monitoring. In poorly segmented environments, such as AI infrastructure, a single breach could disrupt multiple tenants sharing physical GPU servers.
Of the 36,872 exposed IPMI services detected on UDP port 623, 24,650 leaked password-derived authentication material. Further analysis revealed:
- 6,240 servers accepted empty usernames and weak passwords.
- 2,340 instances used easily crackable administrator passwords from public dictionaries.
- 39% of vulnerable servers were located in the U.S., with many being Supermicro systems secured by a 10-character uppercase password printed on chassis labels (username: ADMIN).
While Supermicro acknowledged the risk emphasizing the need to rotate default passwords and isolate management networks it plans to review stronger default password policies for future hardware. HPE, however, provided only an automated response after being notified.
During the investigation, researchers discovered an exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 BTC, though no widespread exploitation has been confirmed. The findings underscore the risks of legacy IPMI authentication and the need to restrict BMC access to isolated networks.
Supermicro cybersecurity rating report: https://www.rankiteo.com/company/supermicro
Hewlett Packard Enterprise cybersecurity rating report: https://www.rankiteo.com/company/hewlett-packard-enterprise
"id": "SUPHEW1785241451",
"linkid": "supermicro, hewlett-packard-enterprise",
"type": "Vulnerability",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology',
'location': 'Global (39% of vulnerable servers in the '
'U.S.)',
'name': 'Supermicro',
'type': 'Hardware Manufacturer'},
{'industry': 'Technology',
'location': 'Global',
'name': 'HPE',
'type': 'Hardware Manufacturer'}],
'attack_vector': 'Exploitation of vulnerable BMC interfaces via IPMI 2.0 '
'protocol',
'data_breach': {'number_of_records_exposed': '24,650 servers leaked '
'password-derived authentication '
'material',
'sensitivity_of_data': 'High (authentication credentials)',
'type_of_data_compromised': 'Password hashes, authentication '
'material'},
'description': 'Researchers at cybersecurity firm Lava identified over 24,650 '
'internet-exposed servers leaking authentication password '
'hashes due to a two-decade-old vulnerability (CVE-2013-4786) '
'in their Baseboard Management Controller (BMC) interfaces. '
'The flaw, rooted in the IPMI 2.0 protocol introduced in 2004, '
'allows attackers to capture authentication responses and '
'crack passwords offline using GPU rigs or similar tools. BMCs '
'enable remote server management including power control, '
'firmware updates, and virtual media mounting, making them '
'high-value targets. Compromised BMCs grant attackers deep '
'system access, bypassing traditional security monitoring. In '
'poorly segmented environments, such as AI infrastructure, a '
'single breach could disrupt multiple tenants sharing physical '
'GPU servers.',
'impact': {'data_compromised': 'Authentication password hashes',
'operational_impact': 'Potential disruption of multiple tenants in '
'poorly segmented environments (e.g., AI '
'infrastructure)',
'systems_affected': '24,650 internet-exposed servers'},
'lessons_learned': 'Risks of legacy IPMI authentication, importance of '
'isolating BMC networks, and rotating default passwords',
'post_incident_analysis': {'corrective_actions': 'Rotate default passwords, '
'isolate BMC networks, '
'restrict BMC access, review '
'default password policies',
'root_causes': '20-year-old vulnerability '
'(CVE-2013-4786) in IPMI 2.0 '
'protocol, default/weak passwords, '
'exposed BMC interfaces'},
'ransomware': {'ransom_demanded': '0.3 BTC (observed in one HPE iLO 4 '
'instance)'},
'recommendations': 'Rotate default passwords, isolate BMC management '
'networks, restrict BMC access to isolated networks, '
'review stronger default password policies for hardware '
'manufacturers',
'references': [{'source': 'Lava cybersecurity firm'}],
'response': {'network_segmentation': 'Recommended to isolate BMC networks',
'remediation_measures': 'Rotate default passwords, isolate '
'management networks, restrict BMC '
'access to isolated networks'},
'title': '24,000 Internet-Exposed Servers Leak Password Hashes Due to '
'20-Year-Old BMC Vulnerability',
'type': 'Data Leak',
'vulnerability_exploited': 'CVE-2013-4786'}