Affected Systems
36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0 protocol on UDP port 623. Affected vendors include Supermicro, HPE iLO, and Dell. 24,650 systems disclose password-derived authentication hashes pre-login due to CVE-2013-4786, an inherent IPMI v2.0 specification flaw with no patch available.
Exploitation Status
Actively exploited. Evidence shows threat actors targeting internet-exposed BMC interfaces, including ransomware operators leaving extortion notes on HPE iLO 4 login pages. HPE iLO servers previously targeted with iLOBleed rootkit since 2020. GPU-based offline cracking recovers HPE iLO factory passwords in under 1 minute, Supermicro passwords in ~1 hour.
Business Impact
Critical infrastructure risk: BMCs operate out-of-band (OOB), independent of host OS, enabling attackers to bypass traditional security controls, survive OS reinstalls, and maintain persistent access below security tool visibility. Over 30% of exposed hashes crackable using common wordlists. 6,240 BMCs use empty usernames with weak passwords; 2,340 use default admin/root credentials. Multi-tenant AI/bare-metal data centers face cross-organization risk via shared infrastructure. Primary exposure in US (14,000+ systems), Germany, China, Netherlands, UK.
Urgency
🔴 Immediate
Recommended Actions
- Block inbound UDP port 623 at network perimeter firewalls immediately to prevent external IPMI access
- Rotate all factory-issued BMC passwords on Supermicro, HPE iLO, and Dell systems during provisioning; avoid predictable formats
- Isolate BMC interfaces to dedicated private management VLANs with strict ACLs limiting access to authorized jump hosts only
- Disable IPMI v1.5 and legacy authentication methods; enforce strong password policies on all BMC accounts including ADMIN and root
- Audit internet-facing assets for UDP 623 exposure using network scanning tools; prioritize remediation for GPU/bare-metal hosting environments
