Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Over 24,000 BMCs Expose IPMI Passwords: Security Alert

Over 24,000 BMCs Expose IPMI Passwords: Security Alert

Posted on July 28, 2026 By CWS

Recent findings have raised alarms in the cybersecurity community due to the discovery of over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the internet. Of these, a concerning 24,650 are leaking password hashes before login, attributed to a flaw in the IPMI v2.0 protocol, as reported by Lava to The Hacker News.

Vulnerability Details and Impact

The vulnerability, known as CVE-2013-4786, carries a CVSS score of 7.5, indicating high severity. This flaw allows attackers to extract password hashes for offline guessing attacks via the HMAC from an RMCP+ Authenticated Key-Exchange Protocol (RAKP) message response. Despite being inherent in IPMI v2.0, introduced in February 2024, no patch exists, as confirmed by Dell.

Security researcher Michael Katchinskiy highlighted that over 30% of the exposed hashes could be broken using common wordlists, impacting modern servers from Supermicro and HPE that still use default passwords. The issue is exacerbated in AI data centers, where exposed BMCs can jeopardize multiple tenants’ workloads due to shared infrastructure risks.

Technical Insights and Threat Landscape

BMCs, critical for managing server hardware, operate independently via protocols like IPMI and Redfish. This independence, known as Out-of-Band management, allows attackers who compromise BMCs to bypass typical security controls and maintain persistent access, even after system reinstallation.

Research indicates that 36,872 IPMI services were exposed on UDP port 623 as of May 6, 2026, with significant concentrations in the U.S., Germany, China, the Netherlands, and the U.K. Alarmingly, nearly 25,000 of these systems exposed authentication materials, facilitating offline credential attacks.

Preventive Measures and Recommendations

To mitigate these risks, security experts recommend blocking UDP port 623 at the network perimeter, rotating factory passwords during provisioning, and restricting BMC access to private management networks. Additionally, disabling legacy IPMI versions and implementing network access controls are crucial steps.

Yakir Kadkoda, CTO of Lava, emphasized the urgent need to secure these management layers as AI infrastructure expands. Organizations have focused on hardening cloud systems but must now prioritize the underlying management controllers to prevent stealthy and persistent cyber threats.

In conclusion, while CVE-2013-4786 is not new, the threat landscape has evolved, making each exposed server a valuable target for attackers. This necessitates proactive security measures to safeguard critical infrastructure.

The Hacker News Tags:BMC, CVE-2013-4786, Cybersecurity, data center security, HPE, IPMI, network security, password security, Ransomware, Supermicro, Vulnerability

Post navigation

Previous Post: Aembit Partners with Snowflake for AI Security Enhancement
Next Post: Hush Security Secures $30M for AI Governance Innovation

Related Posts

China-Linked Group Targets Singapore Telecom in Cyber Attack China-Linked Group Targets Singapore Telecom in Cyber Attack The Hacker News
Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software The Hacker News
XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities The Hacker News
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts The Hacker News
GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets The Hacker News
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple’s iOS 26.6 Patch Secures Against Critical Vulnerabilities
  • Hush Security Secures $30M for AI Governance Innovation
  • Over 24,000 BMCs Expose IPMI Passwords: Security Alert
  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark