Back to advisories

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers direct access to data center infrastructure management.

CRITICALAdvisoryAug 04, 2026
Action required
Scan your environment for internet-exposed BMCs on UDP 623. Immediately disable IPMI remote access or firewall it to trusted networks only. Audit all BMC accounts for default or weak credentials and enforce strong passwords.
Affected products
Baseboard Management Controller (BMC)Lava