Particle.news
Download on the App Store

Thousands of Internet‑Exposed BMCs Leak IPMI Password Hashes

Researchers say the flaw is a decades‑old IPMI v2.0 protocol behavior that cannot be patched, leaving network isolation and credential rotation as the only practical defenses.

Overview

  • Lava's July 28 public report found 36,872 IPMI interfaces reachable on UDP port 623 and 24,650 of those returned password‑derived authentication material before login.
  • The problem stems from CVE‑2013‑4786, an IPMI v2.0 handshake behavior in which a BMC returns an HMAC‑SHA1 response that lets an unauthenticated requester test passwords offline.
  • Modern GPU cracking makes the exposure practical because about one third of captured hashes matched weak or factory formats and were recoverable in tests.
  • Researchers observed at least one active compromise when an exposed HPE iLO page displayed a ransom note, and experts warn BMC access can give attackers persistent, out‑of‑band control that survives OS reinstalls and can alter firmware.
  • There is no protocol patch, so researchers and vendors urge immediate defenses such as blocking UDP 623 at the edge, isolating BMCs on management networks, rotating factory credentials, and disabling legacy IPMI auth while vendors consider default‑password policy changes.