More than 24,000 internet-connected servers have been found exposing authentication password hashes because of a long-standing weakness in the Intelligent Platform Management Interface (IPMI), a remote management technology introduced more than two decades ago.
The flaw, tracked as CVE-2013-4786, allows attackers to capture authentication data from vulnerable Baseboard Management Controller (BMC) interfaces and crack passwords offline using powerful hardware such as GPU systems.
Researchers from cybersecurity startup Lava scanned the internet for IPMI services exposed on UDP port 623 and identified 36,872 publicly accessible hosts. Among them, 24,650 leaked password-derived authentication material that could be used in offline password-cracking attacks. The researchers also discovered that 6,240 systems accepted authentication requests with an empty username, and testing showed many of them relied on weak passwords. In addition, 2,340 servers were protected by administrator passwords that matched entries in publicly available password dictionaries, making them especially easy to compromise.
BMCs are dedicated processors built into server motherboards that allow administrators to manage hardware remotely, even when the operating system is offline. They can be used to power systems on or off, update firmware, and perform other low-level maintenance tasks. Because of this, attackers who gain access to a BMC can potentially take full control of the physical server, install malicious firmware, and bypass many traditional security protections.
Lava warns that compromised BMC credentials may also work across multiple management interfaces within the same organization, allowing attackers to move deeper into enterprise environments. In AI infrastructure, where physical GPU servers are often shared between multiple customers through virtualization or GPU partitioning, a single compromised server could potentially impact several workloads at once if the management network is not properly isolated.
The researchers noted that the United States accounts for roughly 39% of the vulnerable servers they identified. Many of the exposed systems were manufactured by Supermicro and protected by default 10-character uppercase passwords printed on the server chassis, typically paired with the default username “ADMIN.” Although these passwords appear complex, their predictable format makes offline cracking practical. For comparison, Lava estimated that recovering a factory-set HPE password from a captured authentication response could take about one day on an Apple M3-based system.
During the investigation, the researchers also discovered an internet-exposed HPE iLO 4 management interface displaying a ransom note demanding 0.3 BTC. While this does not prove widespread exploitation, it suggests that attackers are actively targeting exposed server management interfaces.
Lava disclosed its findings to both Supermicro and HPE. Supermicro acknowledged the issue and pointed to existing recommendations that advise customers to change default BMC passwords and keep management interfaces off public networks. The company also said it would review stronger default password policies for future hardware. HPE, however, only responded with an automated acknowledgment and did not provide any further communication.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
To reduce the risk of compromise, the researchers recommend ensuring that IPMI and Redfish management interfaces are never exposed directly to the public internet, replacing factory-default BMC passwords with strong unique credentials, restricting access to dedicated management networks, and disabling legacy IPMI authentication methods whenever possible.





