Security · 17h ago
24,650 Server BMCs Leak IPMI Password Hashes to the Internet
Researchers found 36,872 server management interfaces exposed online, with 24,650 leaking IPMI password hashes before login. The flaw allows attackers to crack credentials offline and gain remote control of servers. Affected systems include those from major vendors like Dell, HP, and Supermicro.
Meridian48 take
This is a massive, preventable exposure of critical infrastructure—organizations must audit and firewall their BMCs immediately.
Read the full reporting
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login →
The Hacker News
bmc-securityipmi-exposure