← Back to Feed
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
CVE-2013-4786
July 28, 2026 · The Hacker News · Severity: MEDIUM
Researchers found 36,872 internet-exposed BMCs running IPMI, with 24,650 disclosing password hashes before login due to CVE-2013-4786 — an inherent flaw in the IPMI v2.0 specification. Over 30% of recovered hashes corresponded to passwords crackable within minutes, and since this is a protocol-level design issue, no patch is available from vendors.
Key Takeaways
- 24,650 out of 36,872 internet-exposed BMCs disclose IPMI password hashes before login due to CVE-2013-4786
- CVE-2013-4786 is an inherent flaw in the IPMI v2.0 specification with no available patch from any vendor
- Over 30% of returned hashes corresponded to passwords recoverable within minutes via offline guessing attacks