# The 22-Year-Old Bug That Hands Attackers Keys to Thousands of Data Centers
Some vulnerabilities get patched, then forgotten. CVE-2013-4786 never got the first part right.
Data center security firm Lava published a scan this week showing that more than 24,000 internet-exposed server management interfaces are still hemorrhaging password-derived authentication hashes before a user even logs in — exploitable via a flaw baked into IPMI 2.0 when George W. Bush was in his first term. The vulnerability was publicly documented in 2004. It received a CVE in 2013. In 2026, it is apparently alive and thriving across a meaningful slice of the internet-facing data center management plane.
This is not a story about a new zero-day. It is a story about an industry's collective failure to treat its most privileged infrastructure as an actual attack surface.
## What BMCs Actually Control (And Why Attackers Want Them)
Baseboard Management Controllers sit underneath the operating system. They're the reason a server can be power-cycled remotely, why firmware can be updated on a bricked machine, why a data center operator can read CPU temperatures and fan speeds from across the country. They are the most privileged management layer in most server deployments — and they operate even when the host OS is fully offline.
That privilege matters enormously once an attacker holds BMC credentials. From there, you can reflash firmware, redirect boot media, read memory contents, and establish persistence that survives a complete OS reinstall. The access isn't just administrative — it's pre-OS, pre-hypervisor, effectively pre-everything.
The IPMI protocol (Intelligent Platform Management Interface) is one of several surfaces that expose BMC functionality, along with Redfish and web-based administrative interfaces. Here's the compounding problem: in most implementations, all three share the same credential store. Crack a password through the IPMI attack path, and you likely own the Redfish API and the web console too.
## The Hash Giveaway
The core mechanics of CVE-2013-4786 are worth understanding because they're almost absurdly permissive. During the IPMI 2.0 authentication handshake — specifically in the RAKP (Remote Authenticated Key-Exchange Protocol) step — the BMC returns an HMAC-SHA1 authentication code derived from the account password and session values. An unauthenticated attacker who can reach UDP port 623 can request this response for any account name and receive a hash they can then crack offline.
There's no lockout. No rate limiting in the traditional sense. No need to send a new authentication packet for every password guess — the hash is recovered once, and then cracking happens locally, as fast as your GPU allows.
In 2004, "as fast as your GPU allows" meant something very different. In 2026, a single RTX 4090 can attempt billions of SHA1 hashes per second. Factory-default passwords that might have taken days to crack two decades ago fall in seconds now. The economics of this attack have shifted catastrophically against defenders, and the vulnerability hasn't changed.
Lava's scan surfaced exactly what you'd expect given that math. Of the roughly 37,000 internet-facing IPMI interfaces they identified, 6,240 were accepting an empty username with a weak password. Another 2,340 had named accounts — Admin, root, the usual suspects — with passwords drawn directly from public wordlists. Some BMCs were still running constrained, predictable factory-issued password formats that narrow the cracking search space to something trivial.
## The Management Plane Blind Spot
What makes this more than just a "patch your stuff" story is the structural dynamic behind it. BMC security occupies an awkward position in most organizations' threat models. These devices are treated as infrastructure rather than attack surface — they're provisioned once, often by hardware vendors with factory credentials, and then largely forgotten. Security teams that run tight endpoint detection, robust network monitoring, and aggressive patch cycles on their production systems frequently have no visibility into what's happening on the management plane.
That asymmetry is the real vulnerability. An attacker who gains BMC access doesn't trigger your EDR. They don't show up in your SIEM unless you've specifically instrumented for out-of-band management traffic. They can persist across OS reinstalls, live inside firmware, and operate below every security control you've built on top of the host.
CISA flagged active exploitation of AMI BMC vulnerabilities in the wild relatively recently. Supermicro has patched BMC flaws that were actively abused. N-able just shipped fixes for vulnerabilities that led to direct server compromises. The pattern is consistent: the management plane is under active pressure, and most defenders still treat it as a back-office concern.
The 24,000-plus interfaces currently leaking hashes to anyone with a UDP packet aren't fringe deployments running ancient hardware in a closet somewhere. These are internet-exposed management endpoints in what are presumably production data centers. Some percentage of them are protecting cloud provider infrastructure, colocation tenants, and enterprise workloads.
---
## HackWire Analysis
The instinct when covering CVE-2013-4786 is to treat this as a dusty archive story — vulnerability identified, CVE assigned, responsible parties warned, patch available. But Lava's 2026 scan data shifts the framing entirely. This isn't archaeology. Twenty-four thousand interfaces actively leaking authentication hashes right now is a live operational problem, and the story other coverage is missing is why 2026 is actually a more dangerous moment for this flaw than 2013 was.
Two factors have flipped the calculus. First, GPU cracking performance has improved by orders of magnitude since IPMI 2.0 authentication hashes were first analyzed. Attacks that required days of compute time can now be executed in minutes or hours on consumer hardware. The offline cracking model that made CVE-2013-4786 theoretically interesting in 2013 makes it practically devastating in 2026. Second, the threat actor landscape has matured around exactly this kind of high-privilege, low-visibility access. Ransomware groups and nation-state actors alike have demonstrated consistent interest in pre-OS persistence mechanisms — the kind of durable, detection-resistant foothold that BMC compromise provides.
The underappreciated risk here is credential reuse cascades. Organizations that provisioned their BMCs with shared credentials years ago — or left factory defaults in place — may have rotated those passwords on their OS-level accounts while leaving the management plane untouched. An attacker cracking a single IPMI hash could find that password still valid on a Redfish API, a web console, and potentially against internal systems if the password was reused broadly.
Defenders should treat this as a management plane audit forcing function: enumerate every internet-exposed IPMI interface, rotate credentials, enforce strong unique passwords, and where operationally feasible, take IPMI off public internet entirely. The fact that this vulnerability is 22 years old doesn't make it any less exploitable. It just means the exposure window has been open longer than most people's security careers.
— HackWire Editorial
---
## Related Coverage