UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Server BMC Vulnerability 2026: UK Data Centre Risk

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

Researchers have found more than 24,000 internet-exposed server BMCs leaking crackable authentication data through a two-decade-old IPMI flaw. For UK data centre and enterprise IT teams, this is a fresh reminder that understanding Baseboard Management Controllers is no longer optional background knowledge.

Exposed BMC hosts by risk category
36880 servers27660 servers18440 servers9220 servers0 servers36872 serversTotal Exposed24650 serversLeaking Auth Hash6240 serversEmpty Username2340 serversDictionary Weak PWServers affected
View the data behind this chart
Exposed BMC hosts by risk category
Total ExposedLeaking Auth HashEmpty UsernameDictionary Weak PW
Servers affectedservers36872servers24650servers6240servers2340

A 20-year-old flaw resurfaces at internet scale

The vulnerability at the centre of this story, CVE-2013-4786, is an authentication weakness in IPMI 2.0, a protocol first introduced in 2004. It allows an attacker to request an authentication response from an exposed BMC and then crack the password offline using GPU rigs, with no need to trigger alerts on the target system itself.

Cybersecurity startup Lava scanned for publicly reachable IPMI services on UDP port 623 and found 36,872 internet-exposed hosts. Of those, 24,650 were leaking password-derived authentication material suitable for offline cracking — and researchers say at least a third of that pool yielded working passwords via dictionaries and factory-sticker patterns alone.

Why out-of-band management is a blind spot

BMCs sit beneath the operating system, giving administrators power-on/off, firmware and virtual media control even when a server is powered down. That same independence is precisely why compromise is dangerous: security tooling monitoring the OS and network layer typically has no visibility into this plane at all.

Lava researchers warn that a single compromised BMC can act as a pivot into the wider management network, and that in poorly segmented AI or GPU-sharing environments, one compromised physical host could expose or disrupt several tenants' workloads simultaneously — a scenario UK colocation and cloud providers running shared infrastructure should treat as a live business risk, not a theoretical one.

Breaking down the exposure numbers

The scale is what should concern UK procurement and security teams. Alongside the 24,650 hosts leaking crackable hashes, 6,240 accepted an empty username during authentication and were separately confirmed to run weak passwords, while 2,340 used administrator passwords that matched public dictionaries outright — the digital equivalent of leaving the server room door unlocked.

On the live exposure map reviewed by BleepingComputer, the United States tops the list with 39% of vulnerable servers, but the underlying hardware — iDRAC, iLO and XCC out-of-band interfaces — is deployed identically across UK estates, and Lava found that a large share of exposed BMCs are Supermicro systems using a fixed 10-character uppercase factory password format under the username 'ADMIN', which researchers say remains crackable offline despite its apparent complexity.

Illustration: Server BMC Vulnerability 2026: UK Data Centre Risk

Vendor response has been uneven

Supermicro acknowledged the risk after Lava's June disclosure but pointed to existing administrator guidance on rotating default passwords and isolating management networks, while committing only to review stronger default password policies in future hardware revisions. HPE, by contrast, gave Lava a standard auto-response with no security team follow-up. Researchers also found a live, internet-exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 BTC — not proof of mass exploitation, but clear evidence that opportunistic actors are already probing this attack surface.

This mirrors a pattern UK buyers have seen before: AMI MegaRAC firmware issues, including 2024's CVE-2024-54085 authentication bypass, have previously propagated across Intel, Lenovo and Supermicro product lines from a shared upstream codebase, and some affected models were already end-of-life by the time fixes were needed. Teams planning for server end-of-life should factor BMC firmware support into that decision, not just the host OS lifecycle.

What UK buyers should do this week

The remediation steps are not complex, but they require an accurate inventory first — something many estates lack for out-of-band interfaces specifically. Lava's recommendations, and NVIDIA's own BMC security guidance, converge on the same fundamentals.

  • Take IPMI, Redfish and web-based BMC login pages off the public internet entirely
  • Rotate every default and factory-sticker BMC password, including 'ADMIN' accounts on Supermicro gear
  • Restrict BMC access to isolated, dedicated management networks with no route to production or the internet
  • Disable legacy IPMI authentication where Redfish or a modern equivalent is available
  • Check firmware currency against vendor bulletins — IBM's July 2026 advisory for CVE-2026-7254 (CVSS 5.3) affecting OpenBMC's HTTPS service shows patching activity on this surface is ongoing, not finished

Making BMC exposure part of routine vulnerability management

For most UK organisations, the fix is less about a single patch and more about process. Firms implementing robust vulnerability management should add out-of-band management interfaces to their asset inventory and scanning scope as a named category, not an afterthought bundled with general network devices.

Where in-house resource is stretched, organisations seeking expert IT services or considering hardware maintenance and break-fix support can use a scheduled BMC firmware and credential audit as a low-cost, high-value addition to existing maintenance contracts. Estates with legacy or unsupported hardware may also want to review options for third-party maintenance to keep firmware updates flowing after vendor support lapses, and consider how this exposure fits into a wider zero trust approach to management-plane access.

Share
Key takeaways
  • 24,650 internet-exposed BMCs are leaking crackable authentication hashes via CVE-2013-4786, a 2004-era IPMI flaw.
  • 6,240 hosts accept empty usernames and 2,340 use dictionary-crackable admin passwords — both fixable in a single maintenance window.
  • A live HPE iLO 4 ransom note confirms opportunistic exploitation attempts are already occurring, not just theoretical risk.
  • UK teams should inventory, isolate and patch iDRAC, iLO and XCC interfaces now rather than waiting for a vendor-driven fix, given HPE's minimal disclosure response.
Frequently asked

FAQs — Server BMC Vulnerability 2026

What is CVE-2013-4786 and why does it still matter in 2026?

It is an authentication weakness in IPMI 2.0 that lets an attacker request an authentication response from an exposed BMC and crack the password offline. Despite dating back to a protocol introduced in 2004, over 24,650 internet-exposed servers were still found leaking this material in 2026, showing the flaw was never fully retired from the field.

Which server brands are affected?

Lava's research highlights Supermicro systems using a fixed factory password format under the 'ADMIN' username, and separately notified HPE about exposed iLO interfaces. The underlying IPMI weakness is protocol-level, so any BMC still running legacy IPMI authentication — including iDRAC, iLO and XCC deployments — can be affected.

How urgently should UK data centres act?

Given confirmed ransom-note activity on an exposed HPE iLO 4 instance and the ease of cracking default Supermicro and HPE factory passwords, this should be treated as an immediate operational item: inventory exposed BMCs, take them off the public internet, and rotate default credentials this week.

Is patching alone sufficient?

No. Vendor guidance, including Supermicro's own response to this disclosure, still centres on operational hygiene — rotating passwords and isolating management networks — rather than a single patch. Firmware updates such as IBM's July 2026 OpenBMC fix for CVE-2026-7254 matter, but network isolation and credential rotation remain the primary defence.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111