CuraSec

Act archived

24,000+ internet-exposed BMCs leaking password hashes via 20-year-old flaw

2026-07-28 13:01 UTC · BleepingComputer · read the source ↗ #bmc#ipmi#exposed-infrastructure
  • Engineer — Act: Internet-exposed BMC/IPMI interfaces leaking password hashes represent an immediately exploitable misconfiguration — anyone can harvest and crack those hashes for out-of-band server access. Audit all BMC/IPMI interfaces for internet reachability now and move them behind an OOB management network or VPN; rotate any credentials on exposed units.
  • SOC/IR — Plan: No IOCs or active campaign are cited, so there is no immediate hunt to launch, but external scanning of IPMI port 623 is trivially cheap for attackers. Build or tune detections for inbound connections to BMC management ports from non-management-network sources.
  • Leader — Plan: Twenty-four thousand exposed instances signals a systemic industry hygiene failure; direct engineering to confirm no BMC interfaces in your estate are internet-reachable this quarter, and add management-plane network segmentation to your next control review.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.