24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login via a 22-Year-Old IPMI Flaw
Ars Technica·high signal
New research published August 5 found 24,650 internet-accessible baseboard management controllers leaking authentication hashes prior to login through CVE-2013-4786, a flaw rooted in the IPMI 2.0 spec that has existed for roughly two decades. For at least a third of exposed servers, researchers recovered valid passwords using dictionaries and the default-credential patterns printed on factory chassis stickers — Supermicro units with a 10-character uppercase password and username ADMIN were the most common. BMC firmware lives independently of the host OS, so a backdoor written to BMC flash survives a full OS reinstall.