← Back

Wire · technology

Exposed BMCs hand out password hashes before login

Published

28 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

Researchers discovered that 36,872 baseboard management controllers (BMCs) exposed on the public internet leak password hashes before authentication via CVE-2013-4786, with two-thirds recoverable offline; factory-preset passwords on Supermicro and HPE hardware crack in hours to minutes using commodity GPUs.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Your data centre infrastructure sits on exposed hardware you didn't know was listening. If you run servers on Supermicro or HPE, someone outside your network can grab the factory password hash and crack it in an hour with eight GPUs—then own the machine below your operating system's sight line.

Related on Wire

Topics

Cybersecuritybmc-ipmi-vulnerabilitycredential-exposurepassword-crackingfactory-defaultsdata-center-security