Researchers discovered over 24,650 internet-exposed servers vulnerable to a decades-old IPMI flaw in their Baseboard Management Controller interfaces. The vulnerability allows attackers to leak authentication password hashes for offline cracking, threatening enterprise infrastructure security.
6 reports · 5 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Over 24,000 exposed server BMCs leak password hash via decades-old flaw https://www. bleepingcomputer.com/news/secu rity/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D
Researchers found 24,650 internet-exposed server BMCs vulnerable to a 20-year-old IPMI flaw that leaks password hashes, enabling offline password cracking. https://www. bleepingcomputer.com/news/secu rity/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk. Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered. Listen/Read: https:// hackread.com/ipmi-flaw-exposes -servers-offline-password-cracking/ # Cybersecurity # IPMI # InfoSec # Vulnerability # BMC