24,000 servers exposed by 20-year-old BMC vulnerability

Researchers discovered over 24,650 internet-exposed servers vulnerable to a decades-old IPMI flaw in their Baseboard Management Controller interfaces. The vulnerability allows attackers to leak authentication password hashes for offline cracking, threatening enterprise infrastructure security.

6 reports · 5 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Over 24,000 exposed server BMCs leak password hash via decades-old flaw https://www. bleepingcomputer.com/news/secu rity/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/?utm_so

mastodon:infosec-exchangeother63d ago kagi ↗

Over 24,000 exposed server BMCs leak password hash via decades-old flaw https://www. bleepingcomputer.com/news/secu rity/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D

Researchers found 24,650 internet-exposed server BMCs vulnerable to a 20-year-old IPMI flaw that leaks password hashes, enabling offline password cracking. https://www. bleepingcomputer.com/news/secu

mastodon:infosec-exchangeother63d ago kagi ↗

Researchers found 24,650 internet-exposed server BMCs vulnerable to a 20-year-old IPMI flaw that leaks password hashes, enabling offline password cracking. https://www. bleepingcomputer.com/news/secu rity/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/

📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk. Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with w

mastodon:mstdn-socialother62d ago kagi ↗

📣🚨 A 22-year-old flaw in IPMI 2.0 is still putting servers at risk. Researchers found 24,650 public BMC interfaces exposing authentication data that can be used for offline password cracking, with weak and factory credentials among those recovered. Listen/Read: https:// hackread.com/ipmi-flaw-exposes -servers-offline-password-cracking/ # Cybersecurity # IPMI # InfoSec # Vulnerability # BMC