Researchers Expose 36,872 Baseboard Management Controllers Still Vulnerable to 13-Year-Old IPMI Flaw

Security researchers at data center security firm Lava discovered 36,872 baseboard management controllers reachable from the public internet still exposing a 13-year-old vulnerability in the IPMI 2.0 authentication protocol, with 66% of those systems disclosing authentication hashes that enabled password recovery within minutes, according to findings published today.

TL;DR: Lava’s red team cracked BMC credentials on tens of thousands of internet-exposed servers using CVE-2013-4786, a vulnerability published in 2013, with Supermicro and HPE systems accounting for the majority of impacted infrastructure.

The vulnerability, tracked as CVE-2013-4786 and published in 2013, affects baseboard management controllers—specialized microcontrollers embedded in server platforms that provide out-of-band remote control independent of the host operating system. Of the 36,872 BMCs exposing IPMI discovered by Lava’s researchers, 24,650 disclosed authentication hashes, and more than 30% of those hashes matched “reused, factory-set, or predictably formatted” passwords when tested against common wordlists, the company stated in a security advisory. Nearly 17% of BMCs accepted an empty username field combined with a weak password.

Attack Surface Beneath the Operating System

Baseboard management controllers operate in what Michael Katchinskiy, Lava’s head of security research, described as the “no man’s land” beneath the operating system on enterprise servers. BMCs provide administrators the ability to perform out-of-band management and troubleshooting, update firmware, change configurations, and read hardware sensors without requiring physical access to the server or an operational host OS.

“BMCs control critical infrastructure, yet they often receive far less monitoring and protection than the systems they manage,” Katchinskiy explained in the advisory. “Most security tools monitor the operating system, kernel, containers, and workloads.” Because BMCs operate outside that trust boundary, an attacker gains control beneath the host while remaining largely invisible to tools designed to protect the server layer, he noted.

The vulnerability exists in the IPMI 2.0 authentication protocol, a 22-year-old out-of-band management standard. BMCs can expose multiple management planes—including IPMI, the newer HTTPS-based Redfish, browser-based admin interfaces, and remote console features—that in many cases share the same database and credentials. Lava’s red team researchers gained access to BMCs on Supermicro and HPE servers within minutes by guessing basic passwords or exploiting the hash disclosure flaw.

Diagram showing baseboard management controller positioned beneath server operating system layer with out-of-band management access paths

Vendor Response and Scope

Supermicro, which accounted for more than half of the responding BMCs in Lava’s scan, did not match passwords in the researchers’ wordlist due to a 2019 change that replaced a shared admin password with unique, factory-issued 10-uppercase-letter passwords printed on chassis labels. The researchers reported their findings to impacted parties and to Supermicro, which stated it would review potential improvements to its default password policy for future hardware revisions. Lava confirmed that Supermicro has since fixed the exposure.

The geographic distribution of vulnerable systems spans data centers globally. Lava published an interactive map displaying the internet-exposed BMCs uncovered during the research. The firm did not disclose the number of systems tested in Philippine data center environments, but the vulnerability affects standard enterprise server hardware deployed across Metro Manila, Cebu, and Davao facilities.

Philippine enterprises managing network security solutions face particular risk from BMC compromises because malicious changes made to platform hardware survive OS reinstalls, disk replacements, and standard incident response procedures. Organizations evaluating business continuity and disaster recovery strategies often overlook out-of-band management networks when designing segmentation and monitoring architectures.

Persistent Access Below Detection Layer

The risk extends beyond individual servers in multi-tenant and GPU cloud environments. “AI infrastructure can span thousands of GPUs on shared management networks, with joint storage, high-speed interconnects, and multi-tenant tooling,” Katchinskiy noted. A customer may rent dedicated servers while remaining connected to shared, provider-managed, out-of-band networks where orchestration and provisioning services, credential stores, and admin tools span infrastructure used by numerous customers.

In the environments examined, BMC management networks “lacked effective segmentation, access controls, and monitoring,” Katchinskiy stated. “A single compromised BMC can therefore become a path to additional servers, critical infrastructure, and customer workloads.”

David Shipley of Beauceron Security noted that hardware and software tools often don’t get patched because IT or security teams determine that threat actors can’t exploit them—a common notion around air-gapped systems. “If it’s overlooked, it’s likely because it sits in this weird in-between space between teams,” he said, referring to BMC management falling between networking and systems administration responsibilities.

The vulnerability disclosure arrives as Philippine data center operators manage rapid capacity expansion, with Santos Knight Frank projecting 500 megawatts of capacity by 2028, up from approximately 150 megawatts currently. Organizations deploying new server infrastructure for BPO operations, government agencies, and hyperconverged systems face exposure if BMC credentials and IPMI access remain configured with default or weak settings.

Reading Between the Lines

Philippine enterprises running Supermicro or HPE rack servers for VoIP infrastructure, ERP systems, or hypervisor hosts need to audit BMC access immediately. The 13-year gap between CVE-2013-4786’s publication and its active exploitation mirrors the pattern seen in recent Cisco Unified Communications vulnerabilities, where attackers target below-OS management layers that escape routine security reviews.

The out-of-band management blindspot matters particularly for organizations implementing Executive Order 119 compliance, where data residency mandates assume that servers storing Top Secret and Secret information remain secure at the hardware layer—not just the application and OS layers. A compromised BMC provides persistent access that survives forensic imaging and clean OS reinstalls, defeating containment procedures that assume the threat lives in the operating system.

For IT managers evaluating PLDT’s P24.2-billion data center REIT infrastructure or other colocation providers, the Lava research highlights a diligence question: does the provider segment BMC management networks per customer, or do multi-tenant orchestration tools share credential stores across workloads? A single weak password on a neighboring tenant’s BMC could bridge into an organization’s supposedly isolated rack—an attack path that won’t show up in application-layer vulnerability scans or AI-driven exposure management tools that monitor only the OS upward.

Recent Posts

Contact Us



    About

    Kital is an innovative telecom, IP Telephony, and customized solutions provider to small-to-medium-sized businesses and large enterprises in the Philippines.

    Follow Us on Social Media

    Scroll to Top