CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3363

As cited

Copy frozen at (site build).

vulnerabilities

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Researchers identified over 36,000 internet-exposed Baseboard Management Controller (BMC) interfaces running Intelligent Platform Management Interface (IPMI) protocol. More than 24,650 of these systems leak password-derived authentication hashes prior to login, creating an authentication bypass vulnerability. The exposure affects server management infrastructure across multiple organizations.

Why it matters: Server administrators and infrastructure teams should inventory their BMC/IPMI systems immediately; exposed password hashes enable offline cracking attacks and unauthorized console access to critical hardware.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary