Security · 11h ago
24,650 Exposed BMCs Leak IPMI Password Hashes to Anyone
Researchers at Lava found 36,872 hosts exposing IPMI on UDP port 623, with 24,650 returning password hashes to unauthenticated attackers via CVE-2013-4786. Over 30% of collected hashes were cracked offline using common wordlists and factory passwords. The flaw is in the IPMI v2.0 specification itself, so no patch exists; mitigation requires blocking UDP 623 and isolating BMCs.
Meridian48 take
This is a decade-old protocol flaw that persists because it's treated as a patching problem rather than a network hygiene issue, and the rise of AI infrastructure with exposed BMCs makes it more dangerous than ever.
Read the full reporting
24,650 Exposed BMCs Hand Out IPMI Password Hashes to Anyone Who Asks →
DEV Community
ipmicve-2013-4786