WEDNESDAY, JULY 29, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 11h ago

24,650 Exposed BMCs Leak IPMI Password Hashes to Anyone

By Meridian48 News Desk · Summarised from DEV Community ·

Researchers at Lava found 36,872 hosts exposing IPMI on UDP port 623, with 24,650 returning password hashes to unauthenticated attackers via CVE-2013-4786. Over 30% of collected hashes were cracked offline using common wordlists and factory passwords. The flaw is in the IPMI v2.0 specification itself, so no patch exists; mitigation requires blocking UDP 623 and isolating BMCs.

Meridian48 take
This is a decade-old protocol flaw that persists because it's treated as a patching problem rather than a network hygiene issue, and the rise of AI infrastructure with exposed BMCs makes it more dangerous than ever.
Read the full reporting
24,650 Exposed BMCs Hand Out IPMI Password Hashes to Anyone Who Asks →
DEV Community
ipmicve-2013-4786
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan