22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
ID: 0d1b77b2-a95d-5493-aa57-b9b80eaeb9fd
STIX ID: report--0d1b77b2-a95d-5493-aa57-b9b80eaeb9fd
Feed Name: HackRead
**Executive summary:** Lava's research shows that a flaw in IPMI 2.0 (CVE-2013-4786) causes internet‑accessible Baseboard Management Controllers to leak password-derived authentication data to unauthenticated requests; researchers found tens of thousands of exposed BMCs and were able to recover many weak or factory passwords quickly, creating a high-risk path for full remote server control—recommended mitigations include blocking UDP/623, isolating BMCs on private management networks, replacing factory credentials, and applying vendor updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
