VMTech
+381 11 4183 54024/7 Discuss a project

24,650 internet-exposed BMCs disclose IPMI authentication hashes before login

24,650 internet-exposed BMCs disclose IPMI authentication hashes before login

A July 28, 2026 report from Lava revealed that 24,650 internet-exposed Baseboard Management Controllers disclose password-derived IPMI authentication material before login. The researchers identified 36,872 public IPMI services as of May 6, including more than 14,000 in the United States.

Why exposed BMCs create an exceptional risk

BMCs control server power, firmware, remote consoles, operating system installation, and recovery. Because they operate independently of the host through out-of-band management, a compromised controller can bypass endpoint controls, retain access after an operating system reinstall, and support lateral movement.

The danger is especially acute in GPU clouds and multi-tenant bare-metal environments. One exposed management controller may affect several customers sharing infrastructure, while remaining below the visibility of conventional host-level security tools.

How the IPMI weakness is exploited

CVE-2013-4786, rated 7.5, is inherent to the IPMI v2.0 specification and has no patch. A remote party that can reach UDP port 623 may request an RMCP+ RAKP response containing an HMAC-SHA1 code derived from the account password and known session values, then test guesses offline.

“These management controllers hold the keys to servers and data centers. Once compromised, attackers can operate below the visibility of almost any security tools,” said Lava CTO and co-founder Yakir Kadkoda.

More than 30% of returned hashes corresponded to passwords recoverable through common wordlists or predictable chassis-sticker formats. Lava found 6,240 BMCs exposing matching material for an empty username and 2,340 for named accounts such as ADMIN or root. HPE iLO factory passwords were recovered within a minute on modern GPUs; Supermicro credentials took about an hour.

Immediate defensive priorities

  • Block UDP port 623 at the network edge.
  • Replace factory-issued passwords during provisioning.
  • Disable IPMI 1.5 and other weak legacy options.
  • Restrict BMCs to a private management network.

For businesses operating servers or rented GPU capacity, BMC exposure must be treated as a control-plane risk rather than a routine password issue. Asset discovery, network isolation, credential rotation, and access policies should cover the management hardware beneath every workload.

#security#ipmi#bmc#datacenter
Current metrics
0Views
0Reach
0Likes
0Comments
0Saved
0Shares
Instagram

24,650 internet-exposed BMCs disclose IPMI authentication hashes before login

Open the post on Instagram ↗