Supermicro A.I CyberSecurity Scoring
Supermicro
Company Information
Website:http://www.supermicro.com
Employees number:5,707
Number of followers:202,077
NAICS:3341
Industry Type:Computer Hardware Manufacturing
Homepage:supermicro.com
Supermicro Risk Score (AI oriented)
Between 750 and 799
SupermicroComputer Hardware Manufacturing
Updated:
28/07/2026
28/07/2026
791/1000
Fair
Baa
Supermicro Global Score (TPRM)
xxxx
SupermicroComputer Hardware Manufacturing
Score locked

SupermicroFair
Current Score
791Baa (FAIR)
01000
3 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
792
JULY 2026
791
JUNE 2026
796
Vulnerability
01 Jun 2026 • Supermicro
Supermicro and HPE: Over 24,000 exposed server BMCs leak password hash via decades-old flaw
24,000 Internet-Exposed Servers Leak Password Hashes Due to 20-Year-Old BMC Vulnerability
792
CRITICAL-4
SUPHEW1785241451
24,000 Internet-Exposed Servers Leak Password Hashes Due to 20-Year-Old BMC Vulnerability
Researchers at cybersecurity firm Lava have identified over 24,650 internet-exposed servers leaking authentication password hashes due to a two-decade-old vulnerability (CVE-2013-4786) in their Baseboard Management Controller (BMC) interfaces. The flaw, rooted in the IPMI 2.0 protocol introduced in 2004, allows attackers to capture authentication responses and crack passwords offline using GPU rigs or similar tools.
BMCs enable remote server management including power control, firmware updates, and virtual media mounting making them high-value targets. Compromised BMCs grant attackers deep system access, bypassing traditional security monitoring. In poorly segmented environments, such as AI infrastructure, a single breach could disrupt multiple tenants sharing physical GPU servers.
Of the 36,872 exposed IPMI services detected on UDP port 623, 24,650 leaked password-derived authentication material. Further analysis revealed:
- 6,240 servers accepted empty usernames and weak passwords.
- 2,340 instances used easily crackable administrator passwords from public dictionaries.
- 39% of vulnerable servers were located in the U.S., with many being Supermicro systems secured by a 10-character uppercase password printed on chassis labels (username: ADMIN).
While Supermicro acknowledged the risk emphasizing the need to rotate default passwords and isolate management networks it plans to review stronger default password policies for future hardware. HPE, however, provided only an automated response after being notified.
During the investigation, researchers discovered an exposed HPE iLO 4 login page displaying a ransom note demanding 0.3 BTC, though no widespread exploitation has been confirmed. The findings underscore the risks of legacy IPMI authentication and the need to restrict BMC access to isolated networks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
796
APRIL 2026
796
MARCH 2026
796
FEBRUARY 2026
796
JANUARY 2026
796
DECEMBER 2025
796
NOVEMBER 2025
796
OCTOBER 2025
796
SEPTEMBER 2025
796
SEPTEMBER 2019
795
Vulnerability
01 Sep 2019 • Supermicro
Supermicro
USBAnywhere Attack Vector on Supermicro Servers
792
LOW-3
SUP31410423
A new remote attack vector on Supermicro servers was found that exposed their BMC port over the internet.
More than 47,000 workstations and servers, possibly more, running on Supermicro motherboards were being open to attacks because administrators had left an internal component exposed on the internet.
The company recommended its customers install the latest patches to completely mitigate the USBAnywhere attack vector for good.
A scan of TCP port 623 across the Internet revealed 47,339 BMCs from over 90 different countries with the affected virtual media service publicly accessible.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JANUARY 2013
796
Vulnerability
01 Jan 2013 • Supermicro
Supermicro and HPE: Exposed BMCs hand out password hashes before login
Critical BMC Vulnerability Exposes Thousands of Servers to Offline Password Cracking
792
CRITICAL-4
SUPHEW1785248754
Critical BMC Vulnerability Exposes Thousands of Servers to Offline Password Cracking
A decade-old vulnerability in baseboard management controllers (BMCs) is leaving tens of thousands of servers exposed to credential theft without detection. Researchers at Lava identified 36,872 publicly accessible BMCs via Shodan, with 24,650 nearly two-thirds leaking password-derived authentication hashes before any login attempt. The flaw, tracked as CVE-2013-4786, stems from the IPMI 2.0 handshake, which allows attackers to request HMAC-SHA1 hashes over UDP port 623 without authentication.
Once obtained, these hashes can be cracked offline using GPU-accelerated tools like Hashcat. Lava’s analysis found that a third of the captured hashes were recoverable using public wordlists or predictable factory formats. Over 2,340 endpoints had default accounts (e.g., ADMIN or root) with passwords matching common wordlists, often cracked within minutes. Another one in six exposed hosts accepted empty usernames paired with weak passwords.
### Vendor-Specific Risks
Supermicro BMCs, prevalent in data centers and GPU infrastructure, were the most common in the dataset. While the company replaced shared default passwords years ago complying with California’s SB-327 its current factory passwords follow a 10-character uppercase alphabetic format, creating a keyspace of ~141 trillion possibilities. Lava demonstrated that eight GPUs could brute-force this in under an hour. Testing two adjacent servers at a U.S. bare-metal GPU provider confirmed both used the sticker-based default passwords; the provider patched the exposure after disclosure.
HPE’s iLO controllers fared worse, using shorter factory passwords (uppercase letters + digits) that an eight-GPU lab system cracked in 32 seconds per hash. One exposed iLO 4 interface displayed a ransom note, suggesting prior compromise possibly via iLOBleed, a rootkit known to persist in iLO firmware and enable destructive attacks.
### Impact and Response
BMCs operate below the OS, granting attackers remote power control, firmware flashing, and console access all invisible to host-based security tools. Compromised BMCs can maintain persistence even after system rebuilds, posing severe risks to critical infrastructure, particularly as AI workloads expand.
Supermicro acknowledged the findings in June, reiterating guidance to rotate default passwords and isolate BMCs via VLANs or access controls. The company also plans to review its default password policy for future hardware, potentially introducing longer passwords or expanded character sets.
### Mitigation
Network-level protections are critical: blocking UDP port 623 at the perimeter, disabling legacy IPMI 1.5 and weak cipher suites, and replacing factory credentials during provisioning. BMCs should be restricted to dedicated management networks, VPNs, or bastion hosts, with Redfish over TLS used for secure administration. Without these measures, exposed BMCs remain a low-effort target for credential theft and persistent access.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Supermicro ??
What was Supermicro's A.I Rankiteo Cyber Score in July 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in June 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in May 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in April 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in March 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in February 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in January 2026 ??
What was Supermicro's A.I Rankiteo Cyber Score in December 2025 ??
What was Supermicro's A.I Rankiteo Cyber Score in November 2025 ??
What was Supermicro's A.I Rankiteo Cyber Score in October 2025 ??
What was Supermicro's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Supermicro's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Supermicro ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Supermicro's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?