TL;DR

what: Researchers at Lava scanned the internet on May 6, 2026 and found 36,872 hosts exposing IPMI on UDP port 623, of which 24,650 return password-derived HMAC-SHA1 authentication material to unauthenticated attackers before login via CVE-2013-4786.

impact: Over 30% of collected hashes were cracked offline using common wordlists and factory chassis-sticker formats, handing attackers out-of-band control of servers that survives OS reinstalls and sits below every host-based security tool.

fix: There is no patch because CVE-2013-4786 is a flaw in the IPMI v2.0 specification itself, per Dell's advisory, so the mitigation is blocking UDP 623 at the edge, moving BMCs to an isolated management VLAN, disabling IPMI 1.5, and rotating every factory-issued credential.

who: Anyone running HPE iLO, Supermicro, or Dell iDRAC baseboard management controllers reachable from the internet, with the sharpest exposure at GPU and bare-metal hosting providers running multi-tenant AI infrastructure.