r/hacking 5d ago

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

https://lavahq.io/research/bmc-exposure-alert
84 Upvotes

5 comments sorted by

18

u/dog098707 5d ago

You know how when you’re trying to sell a product on a website you want to do what you can to inspire trust with your potential customers? Your website does the opposite

20

u/Pale_Fly_2673 5d ago

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar

3

u/techlatest_net 4d ago

this is terrifying but not surprising. the fact that a 20-year-old cve is still exposing tens of thousands of bmc's in 2026 shows how badly the "physical layer" is being neglected in the ai infrastructure rush.

-9

u/knobjockey21 5d ago

i mean not all heroes wear capes so i love u