Researchers at Lava found that 24,650 internet-exposed Baseboard Management Controllers (BMCs) leak password-derived authentication material through CVE-2013-4786, a long-known weakness in the IPMI 2.0 handshake over UDP port 623. Across 36,872 publicly reachable IPMI services identified via Shodan, the exposed systems returned data before login that can be used for offline password cracking, bypassing account lockouts and failed-login monitoring. The issue affects out-of-band management interfaces that can grant low-level server control, including remote administration and firmware operations independent of the host operating system.
The researchers said they recovered valid credentials for at least a third of tested systems using dictionaries and factory-password patterns, with Supermicro devices frequently using predictable 10-character uppercase defaults tied to the ADMIN account and HPE iLO systems also showing crackable factory schemes. They also observed an exposed HPE iLO 4 login page displaying a ransom note, indicating at least some BMC interfaces may already have been compromised. Recommended mitigations include removing IPMI and Redfish from the public internet, blocking UDP 623, rotating factory and weak BMC passwords, disabling legacy IPMI authentication options, and restricting management access to isolated networks, VPNs, or bastion hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In a July 2, 2013 blog post, Rapid7 published Dan Farmer's research describing several IPMI/BMC security weaknesses, including retrieval of salted password hashes for offline cracking, abuse of cipher 0, default or anonymous accounts, and Supermicro-specific flaws. The post also explained how BMC compromise can lead to host compromise and persistence via BMC backdoors.
A long-known IPMI 2.0 weakness tracked as CVE-2013-4786 allows exposed Baseboard Management Controller interfaces to return password-derived authentication material before login, enabling offline password cracking.
After identifying the exposure and credential risks, Lava notified Supermicro and HPE and recommended removing IPMI and Redfish from the public internet, rotating factory passwords, isolating management networks, and disabling legacy IPMI authentication.
The researchers found at least one exposed HPE iLO 4 login page displaying a ransom note, indicating unauthorized access or malicious activity targeting publicly reachable BMC management interfaces.
Lava researchers found 36,872 internet-accessible IPMI/BMC services on UDP port 623 and determined that 24,650 exposed material usable for offline password cracking. They also recovered valid passwords for at least a third of affected systems, with Supermicro and HPE devices notably impacted by factory or weak credential patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourcecyberveille.ch
Open sourcedarkreading.com
Open sourcereddit.com
Open sourcelavahq.io
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.