Executive Summary
In July 2026, researchers identified over 24,000 internet-exposed servers leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interfaces. This flaw, CVE-2013-4786, allows attackers to obtain password hashes via the IPMI 2.0 protocol's RAKP authentication, enabling offline password cracking. Exploiting this vulnerability grants attackers control over physical servers, allowing them to alter configurations, apply malicious firmware updates, and compromise systems at a level not monitored by standard security solutions. The United States accounted for 39% of the vulnerable servers, with many being Supermicro systems protected by default credentials susceptible to offline cracking.
The resurgence of this decades-old vulnerability underscores the critical need for organizations to reassess and secure their remote management interfaces. As attackers increasingly target such weaknesses, it is imperative to implement robust security measures, including rotating default BMC passwords, isolating management networks, and disabling legacy IPMI authentication to mitigate potential breaches.
Why This Matters Now
The exploitation of a 20-year-old vulnerability in BMC interfaces highlights the persistent risks associated with outdated security protocols. Immediate action is required to secure remote management interfaces and prevent unauthorized access to critical server infrastructure.
Attack Path Analysis
Attackers exploited the CVE-2013-4786 vulnerability in IPMI 2.0 to obtain password hashes from exposed BMC interfaces, leading to unauthorized access and potential control over server hardware. This access allowed them to escalate privileges within the management plane, facilitating lateral movement across the network. Subsequently, attackers established command and control channels to maintain persistent access, exfiltrated sensitive data, and caused significant operational disruptions.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited the CVE-2013-4786 vulnerability in IPMI 2.0 to obtain password hashes from exposed BMC interfaces, leading to unauthorized access and potential control over server hardware.
Related CVEs
CVE-2013-4786
CVSS 7.5The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
Affected Products:
Supermicro Baseboard Management Controller (BMC) – IPMI 2.0
Hewlett Packard Enterprise Integrated Lights-Out (iLO) – iLO 4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Brute Force: Password Cracking
Unsecured Credentials: Credentials in Files
Valid Accounts
Remote Services: Remote Desktop Protocol
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Password Strength and Complexity
Control ID: 8.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical infrastructure vulnerability exposure through BMC exploitation enables attackers to compromise physical servers, bypass security monitoring, and pivot across management planes in data centers.
Health Care / Life Sciences
HIPAA compliance violations and patient data exposure risks from compromised server BMCs that control medical infrastructure and virtualized healthcare workloads with weak authentication controls.
Financial Services
Banking infrastructure faces severe regulatory compliance breaches and operational disruption as attackers gain physical server control through exposed BMCs, affecting multi-tenant financial processing systems.
Computer Software/Engineering
AI and cloud service providers experience multi-tenant security failures where single BMC compromises affect multiple customer workloads through poorly segmented virtualized GPU server environments.
Sources
- Over 24,000 exposed server BMCs leak password hash via decades-old flawhttps://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/Verified
- BMC Exposure Alerthttps://lavahq.io/research/bmc-exposure-alertVerified
- CVE-2013-4786 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2013-4786Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled access policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the IPMI 2.0 vulnerability may have been constrained by limiting exposure of management interfaces.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the management plane could have been limited by enforcing strict segmentation policies.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across the network could have been constrained by enforcing east-west traffic controls.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may have been limited by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could have been constrained by enforcing strict egress policies.
The overall impact of the attack could have been reduced by limiting the attacker's ability to move laterally and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Server Management
- Data Center Operations
Estimated downtime: N/A
Estimated loss: N/A
Administrator password hashes from over 24,000 internet-exposed servers, potentially leading to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Disable IPMI over LAN if not required to prevent unauthorized remote access.
- • Implement strong, unique passwords for BMC interfaces to mitigate the risk of offline password attacks.
- • Utilize Zero Trust Segmentation to restrict access to management interfaces and limit lateral movement.
- • Deploy East-West Traffic Security controls to monitor and prevent unauthorized internal communications.
- • Establish comprehensive Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



