More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
For at least a third of them, researchers were able to find the correct password using dictionaries and the patterns on factory stickers for default credentials.
The exposed servers are vulnerable to CVE-2013-4786, an IPMI 2.0 authentication weakness rooted in a protocol introduced in 2004.
The security issue allows attackers to request an authentication response that can be used to crack the password offline using dedicated GPU rigs or similar setups.
BMCs and server risks









