Cybersecurity researchers have raised concerns after identifying more than 36,000 Baseboard Management Controller (BMC) interfaces exposed to the public internet through the Intelligent Platform Management Interface (IPMI) protocol. According to a report shared by security company Lava, 36,872 internet accessible server management interfaces were identified, with 24,650 of them exposing password derived authentication hashes before users even complete the login process. Researchers said the issue stems from a weakness in the IPMI v2.0 specification itself, allowing attackers to retrieve authentication data that can later be used in offline password cracking attempts. The flaw is tracked as CVE-2013-4786 and carries a CVSS score of 7.5. Although IPMI v2.0 was introduced in February 2024, Dell noted in its advisory that the issue is an inherent limitation of the protocol specification and currently has no available software patch.
The vulnerability allows unauthenticated attackers to request an authentication exchange from an exposed BMC over UDP port 623 and receive an HMAC based authentication response derived from the account password. Because the authentication data can be collected without completing a login, attackers are able to test password guesses offline without repeatedly interacting with the targeted device. Security researcher Michael Katchinskiy stated that more than 30 percent of the recovered authentication hashes were linked to passwords that could be cracked using publicly available wordlists and predictable factory assigned password formats. Researchers also found that the exposure affected modern HPE and Supermicro servers operated by GPU infrastructure providers, including systems that were still using factory issued passwords. During testing, Lava successfully recovered factory default HPE iLO passwords within one minute using modern GPU hardware, while uniquely assigned Supermicro factory passwords were recovered in approximately one hour. Following the disclosure, Supermicro said it will evaluate possible improvements to its default password policy in future hardware revisions.
BMCs are dedicated management processors built into server motherboards and are responsible for handling remote administration tasks such as power management, firmware updates, operating system installation, remote console access, hardware monitoring, and system recovery. These controllers operate independently of the host operating system through an Out of Band management architecture, making them a critical component in enterprise data centers and cloud infrastructure. Researchers noted that this independent operation also makes compromised BMCs particularly dangerous because attackers can bypass traditional operating system security controls, maintain persistent access even after operating systems are reinstalled, and potentially move laterally across connected infrastructure. Lava warned that the risks are especially significant in modern artificial intelligence data centers where multiple organizations may share the same bare metal infrastructure. A single compromised BMC could expose workloads belonging to multiple tenants while remaining difficult to detect using conventional security monitoring tools. Researchers also referenced previous findings from firmware security company Eclypsium, which highlighted BMCs as attractive attack targets due to their privileged access to server hardware.
As of May 6, 2026, researchers found that more than 14,000 of the exposed IPMI interfaces were located in the United States, with additional systems identified across Germany, China, the Netherlands, and the United Kingdom. Further analysis showed that 6,240 BMCs returned authentication material for an empty username that matched weak password candidates, while another 2,340 systems exposed authentication data for accounts such as ADMIN or root using passwords found in publicly available wordlists. Researchers also noted evidence that threat actors are already targeting internet exposed BMC interfaces, including ransomware operators that left an extortion message on an HPE iLO 4 login page. HPE iLO systems have also previously been targeted by attackers deploying the iLOBleed rootkit. To reduce exposure, security experts recommend blocking UDP port 623 at the network perimeter, replacing factory issued passwords during deployment, disabling older IPMI 1.5 functionality where possible, limiting BMC access to dedicated private management networks, and implementing strict network access controls so that only authorized administrative systems can communicate with management interfaces. Lava said organizations have strengthened operating system and cloud security over the years, but many have overlooked the underlying infrastructure layer that controls critical server operations, making stronger protection of BMC environments increasingly important as AI infrastructure continues to expand.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.