24,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a login attempt even completes, and over 30 percent crack in minutes against common wordlists.
Firmware security firm Lava scanned the internet on May 6, 2026 and found 36,872 exposed Baseboard Management Controller interfaces, the out-of-band management processors that let administrators control a server independent of its operating system. Of those, 24,650 (67 percent) disclosed IPMI v2.0 authentication hashes before login even completed, exploiting CVE-2013-4786, a specification-level flaw that lets a remote attacker retrieve HMAC-SHA1 hashes from RAKP protocol responses over UDP port 623 without repeated authentication attempts, enabling unlimited offline cracking. Researcher Michael Katchinskiy found more than 30 percent of the recovered hashes matched passwords crackable with common wordlists or predictable factory defaults; HPE iLO factory passwords fell in about a minute on modern GPU hardware, Supermicro's in about an hour. Over 14,000 of the exposed systems are in the US. Dell, HPE, and Supermicro are all affected; there is no patch, since the flaw is inherent to the IPMI specification itself.
Why it matters
A password you can crack offline, unlimited attempts, no lockout, no alert, is functionally the same as no password. That's what a spec-level flaw with no available patch means in practice: this isn't a bug you wait out, it's a protocol you have to stop exposing.
BMCs sit underneath the operating system with privileged hardware access, so a cracked IPMI credential isn't a foothold, it's often full control of the physical server. If IPMI is reachable from the internet on any of your infrastructure, that access needs to close now, not after a patch that isn't coming.
Source: The Hacker News