24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Summary
Cybersecurity researchers discovered over 36,000 internet-exposed Baseboard Management Controller (BMC) interfaces using the Intelligent Platform Management Interface (IPMI) protocol. Alarmingly, more than 24,000 of these interfaces disclose password-derived authentication hashes before the login prompt.
IFF Assessment
The disclosure of password hashes before login significantly lowers the bar for attackers to perform brute-force attacks or credential stuffing, potentially leading to unauthorized access and control of server management interfaces.
Defender Context
This finding highlights a critical misconfiguration that leaves sensitive server management interfaces vulnerable. Defenders should urgently audit their internet-facing infrastructure for exposed BMCs and IPMI interfaces, ensuring they are properly secured, firewalled, and that authentication mechanisms are robust, with password hashes never being exposed prior to authentication.