← Back

Wire · technology

Exposed BMCs hand out password hashes before login

Published

28 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

Researchers discovered that 36,872 baseboard management controllers (BMCs) exposed on the public internet leak password hashes before authentication via CVE-2013-4786, with two-thirds recoverable offline; factory-preset passwords on Supermicro and HPE hardware crack in hours to minutes using commodity GPUs.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 2 sources have reported it.

◆ The Wire takeaway

Your data centre infrastructure sits on exposed hardware you didn't know was listening. If you run servers on Supermicro or HPE, someone outside your network can grab the factory password hash and crack it in an hour with eight GPUs—then own the machine below your operating system's sight line.

Coverage

2 sources · 28 Jul 2026

Related on Wire

Topics

Cybersecuritybmc-ipmi-vulnerabilitycredential-exposurepassword-crackingfactory-defaultsdata-center-security