24,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a login attempt even completes, and over 30 percent crack in minutes against common wordlists.
Firmware security firm Lava scanned the internet on May 6, 2026 and found 36,872 exposed Baseboard Management Controller interfaces, the out-of-band management processors that let administrators control a server independent of its operating system. Of those, 24,650 (67 percent) disclosed IPMI v2.0 authentication hashes before login even completed, exploiting CVE-2013-4786, a specification-level flaw that lets a remote attacker retrieve HMAC-SHA1 hashes from RAKP protocol responses over UDP port 623 without repeated authentication attempts, enabling unlimited offline cracking. Researcher Michael Katchinskiy found more than 30 percent of the recovered hashes matched passwords crackable with common wordlists or predictable factory defaults; HPE iLO factory passwords fell in about a minute on modern GPU hardware, Supermicro's in about an hour. Over 14,000 of the exposed systems are in the US. Dell, HPE, and Supermicro are all affected; there is no patch, since the flaw is inherent to the IPMI specification itself.
Why it matters
A password you can crack offline, unlimited attempts, no lockout, no alert, is functionally the same as no password. That's what a spec-level flaw with no available patch means in practice: this isn't a bug you wait out, it's a protocol you have to stop exposing.
BMCs sit underneath the operating system with privileged hardware access, so a cracked IPMI credential isn't a foothold, it's often full control of the physical server. If IPMI is reachable from the internet on any of your infrastructure, that access needs to close now, not after a patch that isn't coming.
Source: The Hacker News
Related on Start with Identity
- BlogCisco FMC shipped with hardcoded credentials, and attackers found them before the patch did
CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers acce
- BlogCISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months
844 MB of agency data in a repo named Private CISA, including a file called importantAWStokens and plaintext internal passwords. Nine automated GitGuardian aler
- BlogA CVSS 10.0 Metabase zero-day handed admin access through the password reset endpoint
CVE-2026-72898 lets an unauthenticated attacker inject SQL through Metabase's password reset endpoint and take administrative control. It was exploited as a zer
- CVECheck Point Security Gateway information disclosure of password hashes
An unauthenticated read on Check Point Security Gateways leaked password hashes, including those used for VPN and local admin. CISA KEV. May 2024. Hash disclosu
- RecipeAdd login to a Next.js app with OIDC
A complete, copy-paste OpenID Connect login for the Next.js App Router using authorization code flow with PKCE, server-side token exchange, and httpOnly cookies
- RankingBest Password Managers for Business: Top 5
The best business password managers in 2026: Bitwarden, Keeper, Dashlane, NordPass, and Zoho Vault. Ranked for team sharing, admin controls, SSO, and value.