All incidents

BMCs expose IPMI password hashes via CVE-2013-4786

vulnerabilityopenJul 28, 2026 — Aug 3, 2026
BMCs Leak Password Hashes via CVE-2013-4786, Threatening Cloud AI

RESEARCHERS from LAVA discovered over 36,000 exposed Baseboard Management Controllers leaking password hashes via a two-decade-old IPMI flaw, CVE-2013-4786.

The vulnerability allows an unauthenticated attacker to query UDP port 623 on the BMC and obtain password-derived hashes that can be cracked offline using common tools.

Because the flaw lies in the IPMI 2.0 specification, it affects a wide range of server hardware regardless of vendor.

According to the exposure report, 36,872 BMCs were found online, with 24,650 of them delivering hash values before any login attempt.

More than 30 % of those hashes were associated with passwords susceptible to cracking, including many devices still configured with factory-default credentials.

Dark Reading notes that the same flaw has been observed in active exploitation, highlighting the risk it poses to AI and GPU cloud infrastructures where BMCs often manage powerful servers.

The privileged nature of BMC access means a successful compromise can lead to full system takeover without triggering typical security alarms.

Administrators should block UDP port 623 from the public internet, replace any factory‑set passwords, disable weak authentication mechanisms and confine BMC management interfaces to private or isolated network segments, as advised in the LAVA exposure alert.

Disabling unnecessary IPMI services and enforcing multi‑factor authentication where supported further reduces the attack surface.

Organisations should also review asset inventories for any overlooked BMCs, ensure firmware is kept up to date as patches become available and maintain continuous monitoring for anomalous BMC traffic.

By limiting exposure and strengthening credentials, the likelihood of credential theft and subsequent server compromise can be markedly reduced.

Intelligence briefing updated Aug 3, 2026

CVE-2013-4786
Root sourcelavahq.io
Timeline Coverage

Swipe to explore timeline