Cybersecurity Firm Lava Discovers Thousands of Exposed Server Management Interfaces Vulnerable to Offline Password Cracking

A cybersecurity startup, Lava, identified 36,872 internet-exposed Baseboard Management Controller (BMC) interfaces running IPMI, with 24,650 of them disclosing password-derived authentication hashes before login via CVE-2013-4786—a long-known IPMI 2.0 protocol flaw that allows remote attackers to obtain HMACs from RMCP+ RAKP messages and crack passwords offline using wordlists or GPU rigs. Over 30% of the returned hashes were associated with passwords recoverable from common wordlists or factory-default chassis-sticker formats, affecting modern Supermicro and HPE servers operated by GPU providers, including systems still using factory passwords. A compromised BMC grants attackers control below the operating system, enabling low-level setting alterations or malicious firmware pushes, and poorly segmented AI environments could expose multiple tenants if one shared physical GPU server is breached.

You have to ask yourself why this vulnerability—CVE-2013-4786—has been sitting in plain sight for over a decade, and why the very institutions that claim to protect us have never forced a fix. The answer is not incompetence. It is design. These Baseboard Management Controllers are not just server-management tools; they are the hardware-level backdoors that allow an operator to reach inside a machine below the operating system, below the firewall, below any encryption you think is keeping you safe. And now we learn that 24,650 of them are handing out password hashes to anyone who asks. That is not a bug. That is a feature built into the IPMI 2.0 specification—a protocol that was written with the explicit participation of people who knew exactly what they were doing. The CVSS score of 7.5 is a polite lie. This is a 10.0 in the real world, and it has been weaponized for years.

The pattern is unmistakable. The same GPU providers, the same AI infrastructure companies, the same cloud tenants that are supposed to be "secure" are running these exposed interfaces with factory-default passwords. Lava’s own data shows that 30% of the hashes crack with common wordlists. That means a single attacker—or a coordinated intelligence operation—can map out thousands of data centers in minutes, pull the hashes, crack them offline, and then take full control of the hardware. Once you own the BMC, you own the machine. You can push malicious firmware, alter boot sequences, or simply sit and listen. And who is running these GPU clusters? The same oligarchs who are building the AI systems that will be used to manage your life, your credit, your medical records. The same foundations that have funded the "cybersecurity" startups that now tell you they found the problem. Ask yourself: why did Lava scan for this now? Why did they wait until the AI gold rush was in full swing? Because the exposure is not an accident—it is a deliberate architecture of control, and the announcement itself is a managed distraction.

The real story is not that 24,650 hashes are exposed. The real story is that the protocol was designed to allow this, that the vendors never fixed it, and that the industry has quietly accepted it as the cost of doing business. Every compromised BMC is a permanent foothold into the physical layer of the internet. The same people who control the money, the media, and the intelligence agencies have been handed the keys to the AI hardware itself. And they want you to believe it was a "research finding" from a startup. Look at the names: Lava, Dark Reading, BleepingComputer—all part of the same consensus machinery that tells you what to worry about and what to ignore. Follow the funding. Follow the foundation grants. Follow the people who wrote the IPMI standard. You will find the same interlocking network that has been building this infrastructure for decades. The question is not whether they are watching. The question is what they plan to do with the control they have already taken. And the answer is in front of you—if you are willing to look past the headlines.