High 7.5
CVE-2013-4786
Exploitation of 20-year-old IPMI vulnerability in Baseboard Management Controllers
Vendor / product: IPMI protocol, Baseboard Management Controllers (BMCs), HPE iLO, Supermicro, Avocent, Huawei, Lenovo, Dell, OpenBMC, H3C, Nvidia, Intel systems
Event date: 2026-07-28
Victim organization: one of the world's largest automotive component manufacturers
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (16)
- Old IPMI vulnerability affects over 24,000 servers techzine.eu · 2026-07-29
- Thousands of server motherboards are vulnerable to controller flaws that could give attackers hardware-level control techspot.com · 2026-08-06
- Buggy microcontrollers making up some of the world's most important servers can be easily backdoored tech.yahoo.com · 2026-08-06
- Thousands of Data Center Controllers Open to Takeover darkreading.com · 2026-07-28
- 20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes cybersecuritynews.com · 2026-07-29
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login thehackernews.com · 2026-07-28
- A 13-year-old flaw is exposing tens of thousands of data center management systems csoonline.com · 2026-07-29
- Factory Passwords Crack in Seconds: 24,650 Data Center BMCs Leak Auth Hashes techtimes.com · 2026-07-29
- IPMI bug in BMCs found after 22 years, exposes 24,000-plus servers scworld.com · 2026-07-28
- 24,650 Exposed BMCs Hand Out IPMI Password Hashes to Anyone Who Asks dev.to · 2026-07-28
- Server remote maintenance: 24,650 servers vulnerable to 20-year-old flaw heise.de · 2026-07-29
- 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking hackread.com · 2026-07-29
- Thousands of servers can be backdoored by exploiting buggy motherboard controllers arstechnica.com · 2026-08-05
- Thousands of servers at risk due to old BMC vulnerabilities techzine.eu · 2026-08-06
- GPU加速放大老舊IPMI協定風險,逾2.4萬個BMC洩漏資料可供離線破解密碼 ithome.com.tw · 2026-07-29
- Out of band, out of mind: DEF CON research calls IPMI a ‘sanctioned backdoor' into enterprise networks networkworld.com · 2026-08-10
References
See CVE-2013-4786 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →