24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

A staggering 24,650 internet-exposed BMCs have been found to disclose IPMI password hashes before login, leaving their owners and users vulnerable to potential breaches. This alarming discovery highlights the growing importance of securing Baseboard Management Controllers (BMCs), a crucial component in modern data centers.

BMCs are essentially small computers embedded within servers, managing power supply, cooling systems, and other critical functions remotely. They often rely on IPMI (Intelligent Platform Management Interface) for remote management, which allows administrators to access BMCs via the internet or local network. However, this convenience comes at a cost: many BMCs have been found to expose sensitive information, including IPMI password hashes, making them easily exploitable by attackers.

The issue arises from the fact that some BMCs’ IPMI configurations default to insecure settings, such as allowing remote access with no authentication or using weak passwords. When an attacker gains access to a BMC’s IPMI interface, they can potentially obtain sensitive information like administrator credentials, network diagrams, and even login hashes for other systems on the same network. In this case, the researchers found that over 24,650 BMCs worldwide had inadvertently disclosed their password hashes, making them vulnerable to brute-force attacks.

The scale of the problem is alarming: these exposed BMCs are scattered across various industries, including finance, healthcare, and government sectors, highlighting the potential for catastrophic breaches. Moreover, the ease with which attackers can exploit this vulnerability underscores the need for immediate action from organizations with internet-exposed BMCs. It’s essential to note that even if an attacker doesn’t obtain the actual password, they can still use the disclosed hash to mount a successful login attempt.

The increasing reliance on AI models in cybersecurity has also led to new concerns about software vulnerabilities. While AI tools have proven valuable in identifying and exploiting weaknesses, they can also inadvertently reveal sensitive information like BMC IPMI passwords. As organizations continue to adopt AI-driven security measures, it’s crucial to prioritize the security of underlying infrastructure components like BMCs.

To mitigate this risk, administrators should review their BMC configurations immediately, ensuring that all IPMI interfaces are properly secured with strong passwords and two-factor authentication enabled. Regular vulnerability scans and penetration testing can also help identify potential issues before they escalate into full-blown breaches.


Source: The Hacker News — 2026-07-28