Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Over 24,000 BMCs Expose IPMI Passwords: Security Alert

Over 24,000 BMCs Expose IPMI Passwords: Security Alert

Posted on July 28, 2026 By CWS

Recent findings have raised alarms in the cybersecurity community due to the discovery of over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the internet. Of these, a concerning 24,650 are leaking password hashes before login, attributed to a flaw in the IPMI v2.0 protocol, as reported by Lava to The Hacker News.

Vulnerability Details and Impact

The vulnerability, known as CVE-2013-4786, carries a CVSS score of 7.5, indicating high severity. This flaw allows attackers to extract password hashes for offline guessing attacks via the HMAC from an RMCP+ Authenticated Key-Exchange Protocol (RAKP) message response. Despite being inherent in IPMI v2.0, introduced in February 2024, no patch exists, as confirmed by Dell.

Security researcher Michael Katchinskiy highlighted that over 30% of the exposed hashes could be broken using common wordlists, impacting modern servers from Supermicro and HPE that still use default passwords. The issue is exacerbated in AI data centers, where exposed BMCs can jeopardize multiple tenants’ workloads due to shared infrastructure risks.

Technical Insights and Threat Landscape

BMCs, critical for managing server hardware, operate independently via protocols like IPMI and Redfish. This independence, known as Out-of-Band management, allows attackers who compromise BMCs to bypass typical security controls and maintain persistent access, even after system reinstallation.

Research indicates that 36,872 IPMI services were exposed on UDP port 623 as of May 6, 2026, with significant concentrations in the U.S., Germany, China, the Netherlands, and the U.K. Alarmingly, nearly 25,000 of these systems exposed authentication materials, facilitating offline credential attacks.

Preventive Measures and Recommendations

To mitigate these risks, security experts recommend blocking UDP port 623 at the network perimeter, rotating factory passwords during provisioning, and restricting BMC access to private management networks. Additionally, disabling legacy IPMI versions and implementing network access controls are crucial steps.

Yakir Kadkoda, CTO of Lava, emphasized the urgent need to secure these management layers as AI infrastructure expands. Organizations have focused on hardening cloud systems but must now prioritize the underlying management controllers to prevent stealthy and persistent cyber threats.

In conclusion, while CVE-2013-4786 is not new, the threat landscape has evolved, making each exposed server a valuable target for attackers. This necessitates proactive security measures to safeguard critical infrastructure.

The Hacker News Tags:BMC, CVE-2013-4786, Cybersecurity, data center security, HPE, IPMI, network security, password security, Ransomware, Supermicro, Vulnerability

Post navigation

Previous Post: Aembit Partners with Snowflake for AI Security Enhancement
Next Post: Hush Security Secures $30M for AI Governance Innovation

Related Posts

Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures The Hacker News
How to Close Threat Detection Gaps: Your SOC’s Action Plan How to Close Threat Detection Gaps: Your SOC’s Action Plan The Hacker News
Malicious NuGet Package Targets Financial Sector Malicious NuGet Package Targets Financial Sector The Hacker News
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware The Hacker News
New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP The Hacker News
MuddyWater Exploits Teams for Credential Theft in Covert Attack MuddyWater Exploits Teams for Credential Theft in Covert Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide
  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark