Researchers have uncovered more than 24,000 servers leaking authentication password hashes from a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Lava HQ has a great write up about it here: https://lavahq.io/research/bmc-exposure-alert
Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:
“The flaw CVE-2013-4786 exposes is in the IPMI RAKP handshake spec, and has been around for 20 years. It returns the password hash enabling offline brute-force attacks you don’t see. The researchers cracked HPE factory passwords in about a day on a cheap M3 Mac. A stronger, non-default password buys more time, but the protocol still hands over the hash; rotation only treats the symptom and the offline brute-force attack is still effective. Vulnerable enterprises should remove these management interfaces from the public internet, update all their passwords and usernames to be complex and non-default, and disable legacy IPMI authentication.”
If you think you might be affected by this, the Lava HQ article has instructions as to how to test, and how to fix this issue. I strongly recommend that you follow these directions ASAP.
Related
This entry was posted on July 29, 2026 at 8:20 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Thousands of Servers Leak Authentication Password Hashes via 20 Year-Old Vuln in BMC Interface
Researchers have uncovered more than 24,000 servers leaking authentication password hashes from a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Lava HQ has a great write up about it here: https://lavahq.io/research/bmc-exposure-alert
Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:
“The flaw CVE-2013-4786 exposes is in the IPMI RAKP handshake spec, and has been around for 20 years. It returns the password hash enabling offline brute-force attacks you don’t see. The researchers cracked HPE factory passwords in about a day on a cheap M3 Mac. A stronger, non-default password buys more time, but the protocol still hands over the hash; rotation only treats the symptom and the offline brute-force attack is still effective. Vulnerable enterprises should remove these management interfaces from the public internet, update all their passwords and usernames to be complex and non-default, and disable legacy IPMI authentication.”
If you think you might be affected by this, the Lava HQ article has instructions as to how to test, and how to fix this issue. I strongly recommend that you follow these directions ASAP.
Share this:
Like this:
Related
This entry was posted on July 29, 2026 at 8:20 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.