www.darkreading.com 7/28/2026, 9:41:40 PM · external

24,000+ BMCs exposed by 20 year old CVE-2013-4786 flaw

24,000+ BMCs exposed by 20 year old CVE-2013-4786 flaw
CyberSIXT Evidence Panel
Primary Source lavahq.io
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article highlights a significant security vulnerability affecting over 24,000 Internet-exposed Baseboard Management Controllers (BMCs) that stem from a flaw over 20 years old (CVE-2013-4786). This vulnerability allows attackers to potentially crack authentication credentials offline, compromising server management systems without being detected by regular security measures.

Researchers from Lava identified the flaw and noted existing exploits in the wild, demonstrating the critical risk BMCs pose due to their privileged access to server hardware. Misconfigured systems, weak passwords, and common username practices compound the issue, emphasizing the need for organizations to isolate BMCs from public access and implement better security practices.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline