{"id":2048,"date":"2026-07-28T16:46:55","date_gmt":"2026-07-28T16:46:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2048"},"modified":"2026-07-28T16:46:55","modified_gmt":"2026-07-28T16:46:55","slug":"24650-internet-exposed-bmcs-disclose-ipmi-password-hashes-before-login","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2048","title":{"rendered":"24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjIZDJmL5vHIaEgakZEwVC-O1KGBidMz7xrUS6MQmj0Nfqx4_WzGlwmz4amGxIwYa2PEJTKr5UsFwkh8lEOoFkjAVwTm38bgmbc_gDW2-__9MBpP5Z6cWQrIjFTe3tKTMEhD2lX3XyTrIe0T4mQDruecN3nCWqHUpkU5NpW5OIzZFy5la9RQnMCsmGkt-n8\/s1700-e365\/bmcs.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.<\/p>\n<p>Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to a vulnerability with the IPMI v2.0 specification itself, according to a <a href=\"https:\/\/lavahq.io\/research\/bmc-exposure-alert\" target=\"_blank\">new report<\/a> Lava shared with The Hacker News. IPMI v2.0 was <a href=\"https:\/\/en.wikipedia.org\/wiki\/Intelligent_Platform_Management_Interface#Version_history\" target=\"_blank\">introduced<\/a> in February 2024.<\/p>\n<p>The issue in question is <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2013-4786\" target=\"_blank\">CVE-2013-4786<\/a> (CVSS score: 7.5), a high-severity information disclosure flaw that enables remote attackers to obtain password hashes for valid accounts and conduct offline password guessing attacks by obtaining the HMAC from an RMCP+ Authenticated Key-Exchange Protocol (RAKP) message response from a BMC.<\/p>\n<p>Per an <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000222162\/data-domain-ipmi-v2-0-password-hash-disclosure\" target=\"_blank\">advisory<\/a> released by Dell, \u00abthis is an inherent problem with the specification for IPMI v2.0,\u00bb with the PC maker noting that there is no patch.<\/p>\n<p>\u00abMore than 30% of the returned hashes were associated with passwords that could be recovered using common wordlists and predictable factory chassis-sticker formats,\u00bb security researcher Michael Katchinskiy said. \u00abThe exposure also affected modern Supermicro and HPE servers operated by GPU providers, including systems that were still using factory-issued passwords.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>BMCs are specialized management processors embedded on a server&#8217;s motherboard that control power, firmware, remote console access, operating system installation, and system recovery. They also act as a crucial component for remote data center automation and uptime to monitor hardware telemetry and facilitate mass deployment of firmware updates and BIOS configurations.<\/p>\n<p>To bridge remote commands to the hardware, the BMC typically communicates using protocols like IPMI and Redfish. As highlighted by firmware security company Eclypsium in <a href=\"https:\/\/thehackernews.com\/2022\/12\/new-bmc-supply-chain-vulnerabilities.html\" target=\"_blank\">late 2022 and early 2023, the privileged position enjoyed by BMCs can also make them ideal attack targets for bad actors looking to gain remote control and deploy persistent malware.<\/p>\n<p>Because BMCs run completely independently of the host operating system, a mechanism known as Out-of-Band (OOB) management, an attacker who manages to successfully compromise an exposed BMC can sidestep traditional security controls, survive operating system reinstalls, and maintain access.<\/p>\n<p>\u00abIn modern AI data centers, where the same bare-metal environment often hosts multiple tenants, a single exposed BMC can potentially place multiple organizations&#8217; workloads at risk through shared infrastructure or lateral movement, making this a significant blind spot in the infrastructure underpinning the AI data center boom,\u00bb the Israeli company said.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi30H9bvrCm9GTcnsYS1juCHvIP9GZNueh1kHoPM93UXh9DrPdpmzIzBXK3iHKyeZD3-Vt7sIEJf2CVCeGL5jrsxqD1FL0Y2b_TpWc227MFOCSG4Af8CNKyrCnQNdexDytZU_kMvvRBoFnZ08CJz9AG69xHODcpS2z00sJ6o-z4Fo0mRdkd8yHoEvgVso74\/s1700-e365\/bmc.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi30H9bvrCm9GTcnsYS1juCHvIP9GZNueh1kHoPM93UXh9DrPdpmzIzBXK3iHKyeZD3-Vt7sIEJf2CVCeGL5jrsxqD1FL0Y2b_TpWc227MFOCSG4Af8CNKyrCnQNdexDytZU_kMvvRBoFnZ08CJz9AG69xHODcpS2z00sJ6o-z4Fo0mRdkd8yHoEvgVso74\/s1700-e365\/bmc.png\" alt=\"\" border=\"0\" data-original-height=\"912\" data-original-width=\"2357\"\/><\/a><\/div>\n<p>At the heart of the research is CVE-2013-4786, a 20-year-old weakness in IPMI 2.0, which an attacker can exploit to recover weak, reused, factory-set, or predictably formatted passwords.<\/p>\n<p>\u00abDuring the authentication process, the BMC can return a message response containing an HMAC-SHA1 authentication code calculated using the account password and session values known to the requester,\u00bb Katchinskiy explained. \u00abAn unauthenticated remote party that can reach UDP port 623 can request this response and test password guesses offline. Unlike repeated online login attempts, the offline process does not require a new request to the BMC for every password candidate.\u00bb<\/p>\n<p>As of May 6, 2026, a search of the public internet for IPMI services exposed on UDP port 623 uncovered 36,872 unique hosts, of which more than 14,000 are located in the U.S. The remaining systems are concentrated in Germany, China, the Netherlands, and the U.K.<\/p>\n<p>Further analysis has determined that nearly 25,000 exposed password-derived authentication materials before login, allowing offline credential cracking. Perhaps even more concerningly, a total of 6,240 BMCs returned authentication material for an empty username that matched a weak password candidate and another 2,340 BMCs returned authentication data for a named account such as ADMIN or root that matched a password from publicly available wordlists.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3-o9La7DYm6jz5qcavVBLvRXUoQLqwrMmrvB529PbUxdg7TJZS3BMjVi4D7vd6V9vlSf_OX48mmXQWPgah_SPITaGgg4AP9YxB2AH-63YeWU39N3DXadwc_2zjIpTwCt0iyTdPZIM-KzKhDf_JDPWDGu3IbYfi1ilQE8Ly29HiKYagSIur-il4k7MMNv8\/s728-e100\/sygnia-d-3.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In tests conducted by Lava, HPE iLO factory passwords were recoverable within a minute using modern GPU hardware, while Supermicro factory passwords were recoverable in approximately one hour despite being <a href=\"https:\/\/www.supermicro.com\/products\/nfo\/files\/IPMI\/BMC_Server_Management_Feature_Guide.pdf\" target=\"_blank\">uniquely assigned<\/a> to each server. In response to the findings, Supermicro said it will evaluate possible improvements to the default password policy for future hardware revisions.<\/p>\n<p>\u00abCVE-2013-4786 is not new, but the risk around it has changed,\u00bb Lava said. GPU cracking has made offline password recovery faster, while modern AI and bare-metal environments have made each exposed server more valuable.<\/p>\n<p>On top of that, evidence has emerged that threat actors are already targeting internet-exposed BMC interfaces, including ransomware operators leaving an extortion note on an HPE iLO 4 login page. It&#8217;s not clear who is behind the activity. That said, HPE iLO servers have been singled out as far back as 2020 to deploy a rootkit called iLOBleed.<\/p>\n<p>To counter the risk, it&#8217;s advised to block UDP port 623 at the network edge, rotate factory-issued passwords during provisioning, disable legacy or weak options such as IPMI 1.5, restrict BMC access to a dedicated private management network, and apply network access controls to ensure only approved administrative systems can reach BMC interfaces.<\/p>\n<p>\u00abOrganizations have spent years hardening cloud workloads and operating systems, but many have overlooked the infrastructure that sits beneath them,\u00bb said Yakir Kadkoda, CTO and co-founder at Lava, in a statement.<\/p>\n<p>\u00abThese management controllers hold the keys to servers and data centers. Once compromised, attackers can operate below the visibility of almost any security tools, maintain persistence even after systems are rebuilt, and potentially move deeper into critical infrastructure. As AI infrastructure rapidly expands, securing this layer has become far more urgent.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2049,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2764,2765,1884,1113,2766,2036,319],"class_list":["post-2048","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bmcs","tag-disclose","tag-hashes","tag-internetexposed","tag-ipmi","tag-login","tag-password"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2048","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2048"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2048\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2049"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2048"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}