Researchers have found more than 24,000 internet-exposed server BMCs leaking crackable authentication data through a two-decade-old IPMI flaw. For UK data centre and enterprise IT teams, this is a fresh reminder that understanding Baseboard Management Controllers is no longer optional background knowledge.
View the data behind this chart
| Total Exposed | Leaking Auth Hash | Empty Username | Dictionary Weak PW | |
|---|---|---|---|---|
| Servers affected | servers36872 | servers24650 | servers6240 | servers2340 |
A 20-year-old flaw resurfaces at internet scale
The vulnerability at the centre of this story, CVE-2013-4786, is an authentication weakness in IPMI 2.0, a protocol first introduced in 2004. It allows an attacker to request an authentication response from an exposed BMC and then crack the password offline using GPU rigs, with no need to trigger alerts on the target system itself.
Cybersecurity startup Lava scanned for publicly reachable IPMI services on UDP port 623 and found 36,872 internet-exposed hosts. Of those, 24,650 were leaking password-derived authentication material suitable for offline cracking — and researchers say at least a third of that pool yielded working passwords via dictionaries and factory-sticker patterns alone.
Why out-of-band management is a blind spot
BMCs sit beneath the operating system, giving administrators power-on/off, firmware and virtual media control even when a server is powered down. That same independence is precisely why compromise is dangerous: security tooling monitoring the OS and network layer typically has no visibility into this plane at all.
Lava researchers warn that a single compromised BMC can act as a pivot into the wider management network, and that in poorly segmented AI or GPU-sharing environments, one compromised physical host could expose or disrupt several tenants' workloads simultaneously — a scenario UK colocation and cloud providers running shared infrastructure should treat as a live business risk, not a theoretical one.
Breaking down the exposure numbers
The scale is what should concern UK procurement and security teams. Alongside the 24,650 hosts leaking crackable hashes, 6,240 accepted an empty username during authentication and were separately confirmed to run weak passwords, while 2,340 used administrator passwords that matched public dictionaries outright — the digital equivalent of leaving the server room door unlocked.
On the live exposure map reviewed by BleepingComputer, the United States tops the list with 39% of vulnerable servers, but the underlying hardware — iDRAC, iLO and XCC out-of-band interfaces — is deployed identically across UK estates, and Lava found that a large share of exposed BMCs are Supermicro systems using a fixed 10-character uppercase factory password format under the username 'ADMIN', which researchers say remains crackable offline despite its apparent complexity.

Vendor response has been uneven
Supermicro acknowledged the risk after Lava's June disclosure but pointed to existing administrator guidance on rotating default passwords and isolating management networks, while committing only to review stronger default password policies in future hardware revisions. HPE, by contrast, gave Lava a standard auto-response with no security team follow-up. Researchers also found a live, internet-exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 BTC — not proof of mass exploitation, but clear evidence that opportunistic actors are already probing this attack surface.
This mirrors a pattern UK buyers have seen before: AMI MegaRAC firmware issues, including 2024's CVE-2024-54085 authentication bypass, have previously propagated across Intel, Lenovo and Supermicro product lines from a shared upstream codebase, and some affected models were already end-of-life by the time fixes were needed. Teams planning for server end-of-life should factor BMC firmware support into that decision, not just the host OS lifecycle.
What UK buyers should do this week
The remediation steps are not complex, but they require an accurate inventory first — something many estates lack for out-of-band interfaces specifically. Lava's recommendations, and NVIDIA's own BMC security guidance, converge on the same fundamentals.
- •Take IPMI, Redfish and web-based BMC login pages off the public internet entirely
- •Rotate every default and factory-sticker BMC password, including 'ADMIN' accounts on Supermicro gear
- •Restrict BMC access to isolated, dedicated management networks with no route to production or the internet
- •Disable legacy IPMI authentication where Redfish or a modern equivalent is available
- •Check firmware currency against vendor bulletins — IBM's July 2026 advisory for CVE-2026-7254 (CVSS 5.3) affecting OpenBMC's HTTPS service shows patching activity on this surface is ongoing, not finished
Making BMC exposure part of routine vulnerability management
For most UK organisations, the fix is less about a single patch and more about process. Firms implementing robust vulnerability management should add out-of-band management interfaces to their asset inventory and scanning scope as a named category, not an afterthought bundled with general network devices.
Where in-house resource is stretched, organisations seeking expert IT services or considering hardware maintenance and break-fix support can use a scheduled BMC firmware and credential audit as a low-cost, high-value addition to existing maintenance contracts. Estates with legacy or unsupported hardware may also want to review options for third-party maintenance to keep firmware updates flowing after vendor support lapses, and consider how this exposure fits into a wider zero trust approach to management-plane access.
- 01BleepingComputer — Over 24,000 exposed server BMCs leak password hash via decades-old flaw · 28 July 2026
- 02NVIDIA — Analyzing Baseboard Management Controllers to Secure Data Center Infrastructure · 28 July 2026
- 03IBM — Security bulletin for CVE-2026-7254 (OpenBMC HTTPS service) · 28 July 2026
- 04The Hacker News — Two new Supermicro BMC bugs allow... · 1 September 2025
- 05TechRadar Pro — BMC flaw left unchecked for 6 years hits Intel and Lenovo servers · 1 January 2025
- 06Ars Technica — Active exploitation of AMI management tool imperils thousands of servers · 1 June 2025
- 07Cisco — IPMI vulnerabilities advisory · 28 July 2026
