24,650 internet-exposed server management chips (iLO/iDRAC/IPMI) hand a crackable password hash to anyone, before login. No patch exists: it is how the protocol authenticates. Get them off the interne

24,650 internet-exposed server management chips (iLO/iDRAC/IPMI) hand a crackable password hash to anyone, before login. No patch exists: it is how the protocol authenticates. Get them off the internet and rotate factory passwords. (CVE-2013-4786) https:// suriq.io/blog/exposed-bmc-ipmi -password-hash-leak # CVE # DataBreach # Phishing # infosec

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

24,650 internet-exposed server management chips (iLO/iDRAC/IPMI) hand a crackable password hash to anyone, before login. No patch exists: it is how the protocol authenticates. Get them off the interne

mastodon:infosec-exchangeother63d ago kagi ↗

24,650 internet-exposed server management chips (iLO/iDRAC/IPMI) hand a crackable password hash to anyone, before login. No patch exists: it is how the protocol authenticates. Get them off the internet and rotate factory passwords. (CVE-2013-4786) https:// suriq.io/blog/exposed-bmc-ipmi -password-hash-leak # CVE # DataBreach # Phishing # infosec