Breach Analysis·29 July 2026

22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft

A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
3 min read
Share
Close-up of a server motherboard chip glowing under red warning lights, representing an exposed baseboard management controller
Breach Analysis

Article record

Breach AnalysisCategory
29 July 2026Published
3 min readReading time
Mark FermorWritten by
Close-up of a server motherboard chip glowing under red warning lights, representing an exposed baseboard management controller

Why it matters

What this means for organisations holding critical data

A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.

Researchers at Lava report that more than 24,000 servers exposed to the public internet are leaking authentication password hashes due to a 22-year-old weakness in their Baseboard Management Controllers (BMCs). The flaw sits inside the Intelligent Platform Management Interface (IPMI) 2.0 specification, introduced in 2004 and formally catalogued years later as CVE-2013-4786.

What Happened

Lava researchers published their findings on 29 July 2026, disclosing that the IPMI 2.0 RAKP authentication exchange returns a salted password hash to any attacker who requests it, without needing to authenticate first. That hash can then be cracked offline, silently, without tripping failed-login alerts on the target server.

The scan found the flaw active on over 24,000 internet-facing BMCs, with roughly one third of the affected servers still using default or dictionary-crackable passwords more than a decade after the CVE was published.

Why BMCs Matter

A BMC is a small, always-on computer embedded on the server motherboard. It can power the machine on or off, mount virtual media, rewrite firmware, and provide remote console access even when the operating system is offline.

Kevin Surace, chief executive officer at TokenCore, told SC Media: "For an attacker, compromising the BMC is close to gaining physical access to the server, often beneath the visibility of endpoint security tools. The industry documented the danger in 2013, but the architectural weakness had already existed for nearly a decade."

Justin Beals, founder and chief executive at Strike Graph, added: "An attacker who cracks a BMC password is not fighting your endpoint detection or network monitoring. They are operating underneath it. BMCs almost never show up in a normal vulnerability scan or asset inventory."

Why This Matters

BMC compromise gives an attacker capabilities that traditional endpoint and network defences cannot see: firmware rewrites, persistence beneath the operating system, and lateral movement across the management network. Chris Jacob, Field CISO at Securonix, put it bluntly: "There is no good reason for this management layer to be exposed to the public internet."

For UK organisations subject to NIS2, DORA and NCSC guidance, an exposed BMC is a governance failure as much as a technical one. It is an asset the security team almost certainly does not inventory, sitting on the internet, using a factory password, with a known unauthenticated hash leak.

The Offline Alternative

The IPMI story is a reminder that any management surface reachable from the internet is eventually reachable by an attacker. Offline Secure Storage (OSS) removes the most sensitive data from that surface entirely. Firevault vaults sit on a Layer 1 physical air gap: there is no BMC on the internet, no remote management plane, and no always-on firmware channel for an attacker to authenticate against. Access happens through defined, human-authorised windows, not through an exposed management port.

Patching IPMI, rotating BMC passwords and isolating management VLANs remain essential hygiene. For the data that would end a business, the safer answer is not a better password on a management interface: it is not having a management interface reachable at all.

Key Takeaways

  • 24,000+ servers exposed: Internet-facing BMCs are leaking password hashes via a 2004-era protocol flaw catalogued as CVE-2013-4786.
  • One third use weak passwords: Default or dictionary-crackable credentials remain common more than a decade after disclosure.
  • Below-the-OS access: A compromised BMC can rewrite firmware and persist beneath endpoint detection.
  • Inventory blind spot: BMCs rarely appear in vulnerability scans or asset registers.
  • Offline removes the surface: Firevault OSS keeps critical data on a Layer 1 physical air gap with no internet-reachable management plane.

Source: SC Media, 28 July 2026; Lava research disclosure, 29 July 2026.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis29 July 20263 min read

22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft

A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.

22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy