
Mass Exploitation of 20-Year-Old BMC Vulnerability Exposes Thousands of Data Centers
cybersecurityvulnerabilityBMCdata_centerhackingCVE-2013-4786SupermicroHPEGPUauthentication
Researchers identified 36,872 internet-exposed Baseboard Management Controllers (BMCs), with 24,650 disclosing password-derived authentication hashes before login due to CVE-2013-4786. Over 30% of these hashes were crackable using common wordlists or predictable factory password formats, affecting modern Supermicro and HPE servers, including those used by GPU providers. The compromised BMCs grant attackers highly privileged access below the operating system, posing risks to broader data center infrastructure. An interactive map of exposed systems was also published.