---
title: "22-Year-Old IPMI Flaw in Server BMCs Exposes 24… | Firevault"
url: https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026
description: "A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving…"
lang: en-GB
---

News · Breach Analysis · 29 July 2026

# 22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft

A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

3 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fipmi-bmc-flaw-exposes-24000-servers-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fipmi-bmc-flaw-exposes-24000-servers-2026&text=22-Year-Old%20IPMI%20Flaw%20in%20Server%20BMCs%20Exposes%2024%2C000%20Machines%20to%20Password%20Theft%0A%0AA%2022-year-old%20authentication%20weakness%20in%20IPMI%202.0%20is%20leaking%20password%20hashes%20from%20more%20than%2024%2C000%20internet-exposed%20Baseboard%20Management%20Controllers%2C%20giving%20attackers%20near-physical%20control%20of%20servers%20beneath%20the%20operating%20system.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fipmi-bmc-flaw-exposes-24000-servers-2026

Image: Close-up of a server motherboard chip glowing under red warning lights, representing an exposed baseboard management controller (https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg)

Close-up of a server motherboard chip glowing under red warning lights, representing an exposed baseboard management controller

Why it matters

## What this means for organisations holding critical data

**Researchers at Lava report** that more than 24,000 servers exposed to the public internet are leaking authentication password hashes due to a 22-year-old weakness in their Baseboard Management Controllers (BMCs). The flaw sits inside the Intelligent Platform Management Interface (IPMI) 2.0 specification, introduced in 2004 and formally catalogued years later as CVE-2013-4786 (https://nvd.nist.gov/vuln/detail/cve-2013-4786).

## What Happened

Lava researchers published their findings on 29 July 2026, disclosing that the IPMI 2.0 RAKP authentication exchange returns a salted password hash to any attacker who requests it, without needing to authenticate first. That hash can then be cracked offline, silently, without tripping failed-login alerts on the target server.

The scan found the flaw active on over 24,000 internet-facing BMCs, with roughly one third of the affected servers still using default or dictionary-crackable passwords more than a decade after the CVE was published.

## Why BMCs Matter

A BMC is a small, always-on computer embedded on the server motherboard. It can power the machine on or off, mount virtual media, rewrite firmware, and provide remote console access even when the operating system is offline.

Kevin Surace, chief executive officer at TokenCore, told SC Media (https://www.scworld.com/news/ipmi-bug-in-bmcs-found-after-22-years-exposes-24000-plus-servers): "For an attacker, compromising the BMC is close to gaining physical access to the server, often beneath the visibility of endpoint security tools. The industry documented the danger in 2013, but the architectural weakness had already existed for nearly a decade."

Justin Beals, founder and chief executive at Strike Graph, added: "An attacker who cracks a BMC password is not fighting your endpoint detection or network monitoring. They are operating underneath it. BMCs almost never show up in a normal vulnerability scan or asset inventory."

## Why This Matters

BMC compromise gives an attacker capabilities that traditional endpoint and network defences cannot see: firmware rewrites, persistence beneath the operating system, and lateral movement across the management network. Chris Jacob, Field CISO at Securonix, put it bluntly: "There is no good reason for this management layer to be exposed to the public internet."

For UK organisations subject to NIS2, DORA and NCSC guidance, an exposed BMC is a governance failure as much as a technical one. It is an asset the security team almost certainly does not inventory, sitting on the internet, using a factory password, with a known unauthenticated hash leak.

## The Offline Alternative

The IPMI story is a reminder that any management surface reachable from the internet is eventually reachable by an attacker. Offline Secure Storage (https://fire-vault.com/offline-secure-storage) (OSS) removes the most sensitive data from that surface entirely. Firevault vaults sit on a Layer 1 physical air gap (https://fire-vault.com/how-it-works/offline-secure-storage): there is no BMC on the internet, no remote management plane, and no always-on firmware channel for an attacker to authenticate against. Access happens through defined, human-authorised windows, not through an exposed management port.

Patching IPMI, rotating BMC passwords and isolating management VLANs remain essential hygiene. For the data that would end a business, the safer answer is not a better password on a management interface: it is not having a management interface reachable at all.

## Key Takeaways

- **24,000+ servers exposed:** Internet-facing BMCs are leaking password hashes via a 2004-era protocol flaw catalogued as CVE-2013-4786.
- **One third use weak passwords:** Default or dictionary-crackable credentials remain common more than a decade after disclosure.
- **Below-the-OS access:** A compromised BMC can rewrite firmware and persist beneath endpoint detection.
- **Inventory blind spot:** BMCs rarely appear in vulnerability scans or asset registers.
- **Offline removes the surface:** Firevault OSS keeps critical data on a Layer 1 physical air gap with no internet-reachable management plane.

_Source: SC Media, 28 July 2026 (https://www.scworld.com/news/ipmi-bug-in-bmcs-found-after-22-years-exposes-24000-plus-servers); Lava research disclosure, 29 July 2026._

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Custody**Named, access-controlled hardware in a Firevault Bunker

**Evidence**Access windows and retrieval events are recorded

**Separation**Physical isolation that satisfies offline copy requirements

**Jurisdiction**Stored where your regulatory position requires

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

Breach Analysis

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min
https://fire-vault.com/news/hcrg-care-group-children-records-cyber-attack-2026

Breach Analysis

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min
https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026

Breach Analysis

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min
https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026

Breach Analysis

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min
https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026#webpage",
    "url": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026",
    "name": "22-Year-Old IPMI Flaw in Server BMCs Exposes 24…",
    "description": "A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft",
        "item": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft",
    "description": "A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.",
    "url": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/9f3f8e37-c6cb-49b6-9a5c-d93ea031020d/ipmi-bmc-vulnerability-2026-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-29T10:23:27.806143+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Breach Analysis",
    "wordCount": 593,
    "keywords": "22-Year-Old, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Researchers at Lava report that more than 24,000 servers exposed to the public internet are leaking authentication password hashes due to a 22-year-old weakness in their Baseboard Management Controllers (BMCs). The flaw sits inside the Intelligent Platform Management Interface (IPMI) 2.0 specification, introduced in 2004 and formally catalogued years later as CVE-2013-4786 . What Happened Lava res",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```