22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

https://hackread.com/wp-content/uploads/2026/07/ipmi-flaw-expose-servers-offline-password-cracking.jpg

A server management feature designed to work when a computer’s operating system is unavailable is exposing password-derived authentication data on thousands of internet-facing systems, according to new research from Lava.

Researchers identified 36,872 publicly accessible Baseboard Management Controller (BMC) interfaces using the Intelligent Platform Management Interface (IPMI). Of those, 24,650 returned password-derived authentication data without requiring successful authentication.

BMC Access Gives Extensive Control Over Servers

A BMC is a small management computer built into a server’s motherboard. Administrators use it to restart machines, open remote consoles, install operating systems, update firmware, and inspect hardware, even when the main server is switched off or unresponsive.

Those capabilities make exposed BMC interfaces high-value targets. Someone who obtains valid login credentials may be able to control the physical server from outside its operating system, where endpoint security software has limited visibility.

SecurityProducts & Services

Lava traced the exposure to CVE-2013-4786, a...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE