bleeping-computer · Crawled Jul 28, 2026
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
1 IoCs
Read original article ↗
AI Summary
Over 24,000 internet-exposed server Baseboard Management Controllers (BMCs) are vulnerable to a 20-year-old flaw (CVE-2013-4786) in IPMI 2.0, allowing attackers to extract password-derived authentication material for offline cracking. Researchers found that many of these systems use weak or default credentials, with Supermicro and HPE systems among the most commonly exposed. Successful compromise of a BMC can enable attackers to control physical servers, pivot to other management interfaces, and disrupt multi-tenant environments, especially in AI infrastructure. Evidence of active exploitation includes an exposed HPE iLO 4 interface displaying a ransom note demanding 0.3 BTC.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 623 | Details → |