RESEARCHERS from LAVA discovered 36,872 exposed Baseboard Management Controllers (BMCs) leaking password-derived hashes via CVE-2013-4786, a significant IPMI 2.0 flaw. The vulnerability allows attackers to crack hashes offline, threatening sensitive systems especially in AI and GPU cloud environments. Key findings include: 24,650 BMCs returned hash values before login, with over 30% having crackable passwords, and some systems running on factory-default passwords.
To mitigate risks, it's advised to block UDP port 623 from public access, replace factory passwords, disable weak authentication, and restrict BMC access to private networks.