#5
The Hacker News
general
July 28, 2026 at 14:41 UTC
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
By [email protected] (The Hacker News)
AI Summary
Researchers identified 36,872 internet-exposed Baseboard Management Controllers (BMCs) running IPMI, of which 24,650 disclose password-derived authentication hashes before login due to a vulnerability dating to 2004. Attackers can perform offline password cracking against these hashes to gain full server management access, including power control and OS reinstallation. The scale of exposure — tens of thousands of servers — and the decades-old nature of the flaw make this a critical data center security issue.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →