[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks-msehtdha":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"7909ba60-c892-44bd-86a8-18776a396b66","Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks","decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks-msehtdha","CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers direct access to data center infrastructure management.","critical","advisory",[12],"CVE-2013-4786",[14,15],"Baseboard Management Controller (BMC)","Lava","Scan your environment for internet-exposed BMCs on UDP 623. Immediately disable IPMI remote access or firewall it to trusted networks only. Audit all BMC accounts for default or weak credentials and enforce strong passwords.",[18],"906932b1-c565-4360-96e4-4ee668798dcf",null,[21],"https:\u002F\u002Fwww.securityweek.com\u002Fdecades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks\u002F","archived","2026-08-06T10:06:03.261+00:00","2026-08-04T10:06:06.074527+00:00","2026-08-06T10:06:31.474206+00:00",[27],{"id":18,"title":6,"url":21}]