22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft
A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.
Article record
Why it matters
What this means for organisations holding critical data
A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.
Researchers at Lava report that more than 24,000 servers exposed to the public internet are leaking authentication password hashes due to a 22-year-old weakness in their Baseboard Management Controllers (BMCs). The flaw sits inside the Intelligent Platform Management Interface (IPMI) 2.0 specification, introduced in 2004 and formally catalogued years later as CVE-2013-4786.
What Happened
Lava researchers published their findings on 29 July 2026, disclosing that the IPMI 2.0 RAKP authentication exchange returns a salted password hash to any attacker who requests it, without needing to authenticate first. That hash can then be cracked offline, silently, without tripping failed-login alerts on the target server.
The scan found the flaw active on over 24,000 internet-facing BMCs, with roughly one third of the affected servers still using default or dictionary-crackable passwords more than a decade after the CVE was published.
Why BMCs Matter
A BMC is a small, always-on computer embedded on the server motherboard. It can power the machine on or off, mount virtual media, rewrite firmware, and provide remote console access even when the operating system is offline.
Kevin Surace, chief executive officer at TokenCore, told SC Media: "For an attacker, compromising the BMC is close to gaining physical access to the server, often beneath the visibility of endpoint security tools. The industry documented the danger in 2013, but the architectural weakness had already existed for nearly a decade."
Justin Beals, founder and chief executive at Strike Graph, added: "An attacker who cracks a BMC password is not fighting your endpoint detection or network monitoring. They are operating underneath it. BMCs almost never show up in a normal vulnerability scan or asset inventory."
Why This Matters
BMC compromise gives an attacker capabilities that traditional endpoint and network defences cannot see: firmware rewrites, persistence beneath the operating system, and lateral movement across the management network. Chris Jacob, Field CISO at Securonix, put it bluntly: "There is no good reason for this management layer to be exposed to the public internet."
For UK organisations subject to NIS2, DORA and NCSC guidance, an exposed BMC is a governance failure as much as a technical one. It is an asset the security team almost certainly does not inventory, sitting on the internet, using a factory password, with a known unauthenticated hash leak.
The Offline Alternative
The IPMI story is a reminder that any management surface reachable from the internet is eventually reachable by an attacker. Offline Secure Storage (OSS) removes the most sensitive data from that surface entirely. Firevault vaults sit on a Layer 1 physical air gap: there is no BMC on the internet, no remote management plane, and no always-on firmware channel for an attacker to authenticate against. Access happens through defined, human-authorised windows, not through an exposed management port.
Patching IPMI, rotating BMC passwords and isolating management VLANs remain essential hygiene. For the data that would end a business, the safer answer is not a better password on a management interface: it is not having a management interface reachable at all.
Key Takeaways
- 24,000+ servers exposed: Internet-facing BMCs are leaking password hashes via a 2004-era protocol flaw catalogued as CVE-2013-4786.
- One third use weak passwords: Default or dictionary-crackable credentials remain common more than a decade after disclosure.
- Below-the-OS access: A compromised BMC can rewrite firmware and persist beneath endpoint detection.
- Inventory blind spot: BMCs rarely appear in vulnerability scans or asset registers.
- Offline removes the surface: Firevault OSS keeps critical data on a Layer 1 physical air gap with no internet-reachable management plane.
Source: SC Media, 28 July 2026; Lava research disclosure, 29 July 2026.
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






