← Back to Feed

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

CVE-2013-4786

July 28, 2026 · The Hacker News · Severity: MEDIUM

Researchers found 36,872 internet-exposed BMCs running IPMI, with 24,650 disclosing password hashes before login due to CVE-2013-4786 — an inherent flaw in the IPMI v2.0 specification. Over 30% of recovered hashes corresponded to passwords crackable within minutes, and since this is a protocol-level design issue, no patch is available from vendors.

Key Takeaways

  • 24,650 out of 36,872 internet-exposed BMCs disclose IPMI password hashes before login due to CVE-2013-4786
  • CVE-2013-4786 is an inherent flaw in the IPMI v2.0 specification with no available patch from any vendor
  • Over 30% of returned hashes corresponded to passwords recoverable within minutes via offline guessing attacks
☕ Buy a Coffee