Over 24,000 Internet-Exposed Servers Leak Password Hashes Due to Two-Decade-Old BMC Vulnerability

A significant cybersecurity vulnerability, rooted in a protocol dating back to 2004, has left over 24,000 internet-exposed servers susceptible to severe security breaches. Researchers have discovered that the Baseboard Management Controller (BMC) interfaces on these systems are leaking authentication password hashes, a critical flaw that allows attackers to gain unauthorized access and potentially control the underlying hardware. The implications of this widespread exposure are far-reaching, particularly for organizations reliant on these servers for critical operations, including those in the burgeoning field of artificial intelligence.

The vulnerability, identified as CVE-2013-4786, targets a weakness within the Intelligent Platform Management Interface (IPMI) 2.0 protocol. IPMI is a standard interface used for out-of-band management of computer systems. It allows administrators to monitor server health, perform diagnostics, and manage hardware functions remotely, even if the main operating system is unresponsive or has crashed. This capability makes BMCs indispensable for data center management, enabling actions such as powering servers on and off, updating firmware, and configuring hardware remotely, independent of the main OS. However, the very feature that offers convenience also presents a substantial attack vector when improperly secured.

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Researchers from the cybersecurity startup Lava have been instrumental in uncovering the extent of this exposure. Their investigation revealed that a substantial number of internet-connected servers are making their BMC interfaces publicly accessible. By scanning for IPMI services on UDP port 623, they identified 36,872 internet-exposed hosts. Critically, a significant portion of these—24,650 servers—were found to be exposing authentication materials that could be exploited for offline password-cracking attacks. This means that even if the password itself isn’t directly visible, the encrypted hash is available, which can then be subjected to brute-force or dictionary attacks using powerful computing resources.

The ease with which some of these passwords can be compromised is alarming. Lava’s findings indicate that 6,240 of the affected servers accepted an empty username during authentication, and subsequent testing confirmed they were also protected by weak passwords. Further analysis revealed that 2,340 instances were using weak administrator passwords that are commonly found in public dictionaries, making them trivial targets for attackers. This suggests a pervasive issue of default or easily guessable credentials being left in place on critical server infrastructure.

A notable pattern observed by Lava researchers involves Supermicro systems, which constitute a large number of the exposed BMCs. Many of these servers are protected by a 10-character uppercase password printed on the chassis label, typically paired with the username ‘ADMIN’. While a 10-character password might seem robust, the researchers point out that the constrained structure, especially when derived from predictable patterns or labels, still makes offline cracking a practical endeavor. For comparative analysis, researchers estimated that recovering an HPE factory password could take approximately one day per captured authentication response using an Apple M3 system, highlighting the computational feasibility of cracking these credentials.

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

The geographical distribution of these vulnerable servers further underscores the global nature of the threat. The United States leads with 39% of the identified vulnerable servers, followed by other regions with significant server deployments. This widespread exposure means that organizations across various industries and geographical locations are at risk.

The potential ramifications of a successful BMC compromise are severe. Attackers gaining access to a BMC can effectively achieve a level of control that bypasses many traditional security measures. They can manipulate low-level hardware configurations, deploy malicious firmware, or even render the server inoperable. In environments where BMCs are poorly segmented from the main network, a single compromised BMC can serve as a pivot point to access the broader management plane, potentially leading to the compromise of numerous interconnected systems.

This is particularly concerning in the context of modern computing environments, such as those used for AI development. Physical GPU servers often support multiple tenants or workloads through virtualization, GPU partitioning, or other sharing mechanisms. A compromise of one physical server’s BMC could therefore disrupt or expose several customer workloads simultaneously. Lava researchers emphasize this point, stating, "In those environments, compromise of one physical server could disrupt or expose several customer workloads." This highlights a critical blind spot in security strategies that focus solely on the operating system and application layers, neglecting the fundamental hardware management interfaces.

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

The researchers have also observed evidence of malicious activity related to these vulnerabilities. During their investigation, Lava encountered an internet-exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 Bitcoin. While this single instance does not confirm widespread exploitation, it serves as a stark indicator that attackers are actively seeking and exploiting these weaknesses. The presence of such notes suggests that compromised BMCs are being used in ransomware attacks, potentially encrypting data or holding systems hostage for financial gain.

In response to these findings, Lava researchers proactively notified affected vendors. They reached out to Supermicro in June, who acknowledged the risks associated with exposed BMCs. The company reiterated its official guidance for administrators, which strongly recommends rotating default BMC passwords and isolating management networks. Supermicro stated that it would review stronger default password policies for future hardware revisions, indicating a potential for improved security in upcoming product lines.

Lava also contacted Hewlett Packard Enterprise (HPE), but according to their report, they received only a standard auto-response and no further follow-up from HPE’s security team. This disparity in vendor response could leave HPE users more vulnerable if proactive measures are not taken by administrators.

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

The timeline of events suggests a growing awareness and concern around this issue. The vulnerability itself, CVE-2013-4786, was documented over a decade ago, highlighting a persistent problem of legacy security issues being exploited in modern infrastructure. The fact that it is still so prevalent underscores a gap in proactive vulnerability management and timely patching or configuration updates across a vast number of deployed servers.

The researchers have put forth several key recommendations for mitigating these risks. Foremost among them is the imperative to keep IPMI and similar remote management interfaces, such as Redfish, off the public internet. Access to these systems should be restricted to isolated, secure management networks. Furthermore, administrators are strongly advised to rotate all factory-default BMC passwords immediately upon deployment and to implement strong, unique passwords for all management interfaces. Disabling legacy IPMI authentication protocols where possible is also recommended to further harden these systems.

The implications for organizations, especially those managing large server fleets or operating in high-security environments, are significant. The discovery underscores the need for a comprehensive security posture that extends beyond the traditional network perimeter and application layers. A layered security approach, which includes robust hardware security and diligent management of out-of-band management interfaces, is crucial. The potential for attackers to gain deep, low-level control of hardware means that even the most sophisticated software-based security solutions could be bypassed.

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

This widespread exposure also highlights a broader challenge in the cybersecurity landscape: the long tail of legacy vulnerabilities. Technologies and protocols that have been around for decades continue to underpin critical infrastructure, and if not diligently managed and secured, they can become significant liabilities. The ongoing reliance on IPMI, despite its age, means that this vulnerability will likely remain a threat until concerted efforts are made by vendors and end-users to secure these interfaces.

For organizations operating AI environments, the stakes are particularly high. The compute-intensive nature of AI workloads often necessitates powerful, interconnected server infrastructure. A compromise at the BMC level could lead to significant disruption of training processes, data breaches, or even the manipulation of AI models themselves. The ability for attackers to pivot from a single compromised server to an entire cluster of machines presents a catastrophic scenario for data integrity and operational continuity.

In conclusion, the revelation of over 24,000 internet-exposed servers leaking password hashes due to a 20-year-old BMC vulnerability is a critical cybersecurity alert. It serves as a stark reminder that fundamental security hygiene, including the secure configuration of management interfaces and the diligent rotation of default credentials, remains paramount. The findings by Lava researchers underscore the need for continuous vigilance, proactive security audits, and a comprehensive understanding of an organization’s entire attack surface, from the operating system down to the hardware management layer. Vendors also bear a responsibility to address legacy vulnerabilities and to implement stronger default security measures in their hardware to prevent such widespread exposures in the future. The ongoing threat landscape demands a robust and multi-faceted approach to security, ensuring that even the oldest protocols are not overlooked in the defense against sophisticated cyber adversaries.

Related Posts

Arista Networks Patches Critical Command Injection Vulnerability Exploited in the Wild

Arista Networks has urgently addressed a critical security vulnerability within its on-premises VeloCloud Orchestrator (VCO) deployments, a flaw that has already been actively exploited by malicious actors. The vulnerability, identified…

Hackers Exploit FastJson Zero-Day Vulnerability to Execute Remote Code on US Firms

Cybercriminals are actively leveraging a critical zero-day vulnerability within the widely used FastJson Java library, enabling them to execute arbitrary code on targeted systems without requiring user interaction or elevated…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

Controversy Erupts as Viral Video Targets Olympia LGBTQ+ Youth Organization, Igniting Debate Over Funding and Political Messaging

Controversy Erupts as Viral Video Targets Olympia LGBTQ+ Youth Organization, Igniting Debate Over Funding and Political Messaging

User Puts Microsoft’s Unreleased NVIDIA N1X-Equipped Surface Laptop Ultra To Test; Discovers Chip Being Held Back by Unfinished Drivers

  • By admin
  • July 28, 2026
  • 1 views
User Puts Microsoft’s Unreleased NVIDIA N1X-Equipped Surface Laptop Ultra To Test; Discovers Chip Being Held Back by Unfinished Drivers

Claude AI Faces Scrutiny as Sensitive User Chats and Artifacts Exposed Publicly via Google Search Indexing.

Claude AI Faces Scrutiny as Sensitive User Chats and Artifacts Exposed Publicly via Google Search Indexing.

Over 24,000 Internet-Exposed Servers Leak Password Hashes Due to Two-Decade-Old BMC Vulnerability

Over 24,000 Internet-Exposed Servers Leak Password Hashes Due to Two-Decade-Old BMC Vulnerability

Hugging Face Platform Found to Facilitate Non-Consensual Intimate Imagery Generation Due to Lax Safeguards

Hugging Face Platform Found to Facilitate Non-Consensual Intimate Imagery Generation Due to Lax Safeguards

Snowflake Summit 2024 Highlights Breakthroughs in AI Assisted Engineering and Collaborative Data Platforms

Snowflake Summit 2024 Highlights Breakthroughs in AI Assisted Engineering and Collaborative Data Platforms