Security · 1h ago
24,000+ Exposed BMCs Leak Password Hashes via Decade-Old Flaw
Attackers can exploit CVE-2013-4786 to steal password hashes from exposed IPMI/BMC interfaces over UDP/623. A recent scan found 24,650 devices leaking authentication material, with 2,340 using weak passwords. Offline GPU cracking allows attackers to gain low-level server management access without triggering OS alerts.
Meridian48 take
This is a reminder that old vulnerabilities in critical infrastructure remain exploitable at scale, and the real risk is the lack of network segmentation for out-of-band management interfaces.
Read the full reporting
IPMI/BMC Authentication Hash Leak: Stealing Out-of-Band Server Management via Offline Cracking →
DEV Community
ipmi-bmc-securitycve-2013-4786