24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Summary

Cybersecurity researchers discovered over 36,000 internet-exposed Baseboard Management Controller (BMC) interfaces using the Intelligent Platform Management Interface (IPMI) protocol. Alarmingly, more than 24,000 of these interfaces disclose password-derived authentication hashes before the login prompt.

IFF Assessment

FOE

The disclosure of password hashes before login significantly lowers the bar for attackers to perform brute-force attacks or credential stuffing, potentially leading to unauthorized access and control of server management interfaces.

Defender Context

This finding highlights a critical misconfiguration that leaves sensitive server management interfaces vulnerable. Defenders should urgently audit their internet-facing infrastructure for exposed BMCs and IPMI interfaces, ensuring they are properly secured, firewalled, and that authentication mechanisms are robust, with password hashes never being exposed prior to authentication.

Read Full Story →