Over 24,000 internet-exposed Baseboard Management Controller interfaces leak IPMI authentication hashes without requiring login credentials, creating a severe attack vector for server infrastructure compromise.
Cybersecurity researchers identified 36,872 BMC management interfaces running the Intelligent Platform Management Interface protocol exposed to the public internet. Of these, 24,650 systems disclose password-derived authentication hashes during the initial connection phase, before any login occurs. This vulnerability allows attackers to capture cryptographic material remotely and offline crack these hashes to gain administrative access to critical server hardware.
BMCs are out-of-band management systems that provide physical server control independent of the operating system. They handle functions like power cycling, remote console access, and firmware updates. IPMI is the standard protocol enabling this remote management. Exposure of BMC interfaces directly to the internet represents a severe misconfiguration, as these systems should remain isolated on trusted internal networks only.
The hash disclosure flaw is particularly dangerous because it bypasses traditional authentication steps. Attackers need not interact with password prompts or trigger failed login attempts. They simply connect to the exposed IPMI port and collect hashes passively. Modern hardware accelerators and large wordlists make cracking these hashes feasible for many targets, especially if organizations used weak default credentials during BMC provisioning.
Organizations operating exposed BMCs face immediate risks. Compromised BMC credentials grant attackers lights-out administrative access, enabling them to reboot servers, modify BIOS settings, install persistence mechanisms, or wipe drives entirely. Such access persists even if operating systems are patched or firewalls are reconfigured, since the BMC operates at the hardware level.
Remediation requires immediate action. Organizations should scan their networks for internet-exposed IPMI services using tools like Shodan or Censys. All exposed BMCs must be
