securityonline.info 8/3/2026, 3:21:42 PM · external

BMCs Leak Password Hashes via CVE-2013-4786, Threatening Cloud AI

BMCs Leak Password Hashes via CVE-2013-4786, Threatening Cloud AI
Developing story vulnerability 2 articles tracked
BMCs expose IPMI password hashes via CVE-2013-4786
CyberSIXT Evidence Panel
Primary Source lavahq.io
CISA KEV Not in KEV
Patch Patch Status Unknown

RESEARCHERS from LAVA discovered 36,872 exposed Baseboard Management Controllers (BMCs) leaking password-derived hashes via CVE-2013-4786, a significant IPMI 2.0 flaw. The vulnerability allows attackers to crack hashes offline, threatening sensitive systems especially in AI and GPU cloud environments. Key findings include: 24,650 BMCs returned hash values before login, with over 30% having crackable passwords, and some systems running on factory-default passwords.

To mitigate risks, it's advised to block UDP port 623 from public access, replace factory passwords, disable weak authentication, and restrict BMC access to private networks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline