discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. Researchers were able to find the correct password using dictionaries and the patterns on fact…

By Bill Toulas·Jul 28·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Image: bleepingcomputer.com

A 20-year-old vulnerability in the Baseboard Management Controller (BMC) interface of internet-exposed servers is leaking authentication password hashes, allowing attackers to request an authentication response that can be used to crack the password offline.

Why it matters

This story matters because it highlights the importance of securing internet-exposed servers and the potential risks of using default passwords. It also shows how a decades-old vulnerability can still have a significant impact on modern systems.

Imagine you have a super powerful tool that can unlock any door in a building. But, the tool is only as good as the lock it's trying to unlock. If the lock is weak, the tool can easily open it. In this case, the lock is the password of the server, and the tool is the vulnerability in the Baseboard Management Controller (BMC) interface. If the password is weak, the tool can easily crack it and gain access to the server.

Analysis

A Decades-Old Flaw Exposed

The recent discovery of over 24,000 internet-exposed servers leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface is a stark reminder of the importance of securing modern systems. The vulnerability, which affects IPMI 2.0 authentication, allows attackers to request an authentication response that can be used to crack the password offline using dedicated GPU rigs or similar setups.

BMCs are processors built into a server motherboard that allow administrators to remotely manage the system independent of the operating system. They support low-level actions such as powering servers on/off, updating firmware, or mounting virtual media. Access to BMCs can give attackers control over physical servers, letting them change low-level configurations, apply malicious firmware updates, and compromise the system at a layer not monitored by security solutions.

Researchers at cybersecurity and infrastructure startup Lava say that in real-world settings, recovered credentials may work across multiple management interfaces within the same environment, and that a single compromised BMC could serve as a pivot point to the broader management plane. In AI environments with poorly segmented infrastructure, attackers could affect multiple tenants simultaneously.

The Risks of Default Passwords

The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004. The security issue allows attackers to request an authentication response that can be used to crack the password offline using dedicated GPU rigs or similar setups. BMCs and server risks BMCs are processors built into a server motherboard that allow administrators to remotely manage the system independent of the operating system. They support low-level actions such as powering servers on/off, updating firmware, or mounting virtual media. Access to BMCs can give attackers control over physical servers, letting them change low-level configurations, apply malicious firmware updates, and compromise the system at a layer not monitored by security solutions.

Researchers at Lava say that in real-world settings, recovered credentials may work across multiple management interfaces within the same environment, and that a single compromised BMC could serve as a pivot point to the broader management plane. In AI environments with poorly segmented infrastructure, attackers could affect multiple tenants simultaneously.

The Impact of the Flaw

The researchers found 36,872 internet-exposed hosts, of which 24,650 exposed password-derived authentication material that could be used to perform offline password-cracking attacks. According to researchers at Lava, 6,240 of the hosts accepted an empty username during authentication, and subsequent testing confirmed that they were also protected by weak passwords. A number of 2,340 instances used weak administrator passwords that matched public dictionaries, making them very easy to breach.

On a live exposure map seen by BleepingComputer, the United States is at the top of the list with 39% of the vulnerable servers. Lava researchers note that a large number of the BMCs it found exposed online are Supermicro systems protected by a 10-character uppercase password printed on the chassis label, with the username ‘ADMIN’ in all instances. They argue that while this format theoretically provides ample headroom, its constrained structure still makes offline cracking practical.

Key points

  • Over 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
  • Researchers were able to find the correct password using dictionaries and the patterns on factory stickers for default credentials.
  • The vulnerability affects IPMI 2.0 authentication and allows attackers to request an authentication response that can be used to crack the password offline.
  • The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.
  • The researchers found 36,872 internet-exposed hosts, of which 24,650 exposed password-derived authentication material that could be used to perform offline password-cracking attacks.
The Upside

If the vulnerability is patched quickly and all affected servers are secured, the risk of exploitation can be significantly reduced. Additionally, if all default passwords are rotated and access to management networks is restricted, the likelihood of successful attacks can be minimized.

The Downside

If the vulnerability is not patched quickly, the risk of exploitation can increase, and more servers may be compromised. Additionally, if default passwords are not rotated and access to management networks is not restricted, the likelihood of successful attacks can increase.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityvulnerabilitybmcipmipasswordhashexploitationattackservermanagement

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Jul 28, 2026

Source

bleepingcomputer.com

Share

Topics

securityvulnerabilitybmcipmipasswordhashexploitationattackservermanagement

Related

More from this desk

Jul 28·thehackernews.com

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Kaspersky attributes a fresh wave of attacks across the Middle East, Africa, and South Asia to Iranian group Nimbus Manticore, which deployed a new Windows backdoor called NightLedger alongside custom WebSocket tunnelers BridgeHead and ArcBridge to covertly relay traffic …

Jul 28·schneier.com

Axon Is Another License Plate Surveillance Company

Bruce Schneier warns that municipalities swapping Flock license-plate readers for Axon cameras aren't reducing surveillance, calling it a switch from one surveillance vendor to another with similar privacy consequences.

Jul 28·bleepingcomputer.com

Data breach at medical billing firm MCBS affects 1.26 million people

Medical billing firm MCBS disclosed a 2025 network breach exposing sensitive information of over 1.2 million people. The company reported that 1,261,464 people have been impacted. Exposed data includes full name, physical address, social security number, date of birth, an…

Jul 28·thehackernews.com

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

A critical security issue has been discovered in TeamCity, a popular continuous integration and continuous deployment (CI/CD) tool. The vulnerability, assigned CVE-2026-63077, affects all TeamCity On-Premises versions and could allow attackers to run OS commands without l…