By Interestana AI Editorial — AI-drafted, human-overseen. How we report
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes

Cybersecurity researchers have identified a significant vulnerability affecting internet-exposed Baseboard Management Controllers (BMCs), with over 36,000 management interfaces running the Intelligent Platform Management Interface (IPMI) protocol accessible to the public internet. Specifically, 24,650 of these 36,872 internet-exposed server management interfaces were found to disclose password-derived authentication hashes prior to a user attempting to log in. This disclosure means that attackers could potentially obtain these hashes and use brute-force or dictionary attacks to crack the original passwords, gaining unauthorized access to critical server management functions. The findings were published by researchers who conducted a scan of the internet to identify these exposed systems. BMCs are essential components in modern servers, providing out-of-band management capabilities that allow administrators to monitor, control, and troubleshoot servers remotely, even if the main operating system is unresponsive or powered off. IPMI is a standardized interface for these management functions. The exposure of password hashes before authentication is a critical security flaw because it bypasses the first layer of defense, which is typically the password itself. Instead of needing to guess or steal a password, an attacker can acquire a pre-hashed version of the password. Modern password cracking techniques can efficiently process these hashes, especially if the original passwords were weak or commonly used. The researchers did not name specific organizations or individuals affected by this vulnerability, but the sheer number of exposed BMCs suggests a widespread issue across various data centers and server deployments. The implications of unauthorized access to BMCs are severe, as it can lead to complete server compromise, data theft, system manipulation, or the use of compromised servers in botnets. The discovery highlights a persistent challenge in securing the vast and complex infrastructure that underpins the internet and enterprise IT systems. Many of these systems are legacy or have been deployed without adequate security configurations, leaving them vulnerable to automated scanning and exploitation. The researchers' work underscores the importance of regular security audits and the need for proper network segmentation and access controls to prevent such sensitive management interfaces from being exposed to the public internet. Organizations are urged to review their network configurations, ensure BMCs are not directly accessible from the internet, and implement strong password policies and multi-factor authentication where available for all management interfaces. The specific number of 24,650 systems disclosing hashes is a concrete metric indicating the scale of the problem, representing a substantial attack surface for malicious actors. The total of 36,872 internet-exposed IPMI interfaces further emphasizes the broad reach of this potential vulnerability. This situation calls for immediate attention from IT security professionals responsible for server infrastructure management.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.