
CVE-2013-4786: IPMI BMC — Remote Hash Theft Risk (June 2024)
CVE-2013-4786 — IPMI 2.0 Baseboard Management Controller
CVE-2013-4786 is a high-severity vulnerability in the IPMI 2.0 protocol used by Baseboard Management Controllers (BMCs). It enables unauthenticated remote attackers to extract authentication hashes from server management interfaces, allowing offline password cracking and potential privileged access. Over 24,000 internet-facing BMCs are currently exposed. No evidence of active exploitation has been reported, but the risk is critical due to the ease of exploitation and widespread exposure.
Attack Vector
Attackers scan for IPMI 2.0 interfaces exposed to the internet. By sending crafted packets, they can remotely retrieve authentication hashes without valid credentials or repeated login attempts. These hashes can be cracked offline, especially if weak, default, or reused passwords are present. Over 6,000 hosts accept empty usernames with weak passwords, and more than 2,000 have accounts with common passwords, drastically increasing the likelihood of compromise. No user interaction is required, and exploitation does not trigger account lockouts or alerts by default.
Who Is at Risk
Any organization operating data centers with BMCs using IPMI 2.0 protocol is at risk, especially if management interfaces are internet-accessible. Affected systems are found globally, with over 24,000 exposed hosts identified. Devices accepting empty usernames or using default/factory credentials are especially vulnerable. Organizations relying on legacy hardware or lacking strict network segmentation are at heightened risk.
Patch & Mitigate
- Patch: Apply the latest firmware updates from your BMC vendor. Remove IPMI interfaces from public internet exposure immediately. No universal patch deadline is published; act now.
- Workaround: Restrict IPMI access to trusted management networks only. Enforce strong, unique passwords and disable unused accounts.
- Detect: Monitor for external connections to TCP port 623 (IPMI). Review logs for authentication attempts, especially from unfamiliar IPs. Audit for use of default or weak credentials.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers leverage exposed BMC interfaces to gain a foothold.
- TA0006 — Credential Access: Hashes are extracted and cracked offline for privileged access.
- TA0007 — Discovery: Attackers may enumerate additional management interfaces once inside.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

