The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers found over 36,000 server management interfaces (BMCs) exposed to the internet, with nearly 25,000 leaking password hashes before login due to an old flaw in the IPMI 2.0 specification known as CVE-2013-4786.
- The flaw lets remote attackers grab password hashes and crack them offline, and tests showed factory-set passwords on HPE and Supermicro servers could be recovered within minutes to about an hour using GPU hardware.
- Because BMCs operate independently of the operating system, a compromise could let attackers bypass security controls, survive system rebuilds, and potentially endanger multiple tenants in shared AI data centers.
- More than 14,000 of the exposed hosts are in the U.S., and there is evidence attackers, including ransomware operators, are already targeting such interfaces.
What to watch next
- Whether Supermicro follows through on evaluating changes to its default password policy for future hardware.
- Whether exposed hosts are actually compromised, given the ransom note found on an HPE iLO 4 login page.
- Whether organizations adopt mitigations like blocking UDP port 623 and restricting BMC access to private management networks.
Coverage1
1 report
English national1
All filed from India
Named United States · Germany · China · Netherlands · United Kingdom · BMC · Dell · HPE · IPMI · Supermicro · Eclypsium · Lava
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
