Plan
archived
24,650 Internet-Exposed BMCs Leak IPMI Password Hashes Pre-Auth
- Engineer — Plan: The IPMI RAKP pre-auth hash disclosure flaw is a known long-standing weakness, but this research quantifies how many organizations still expose BMC interfaces directly to the internet. Audit all BMC/IPMI management interfaces for internet reachability and enforce firewall or out-of-band network isolation; rotate IPMI credentials on any system that may have been exposed.
- SOC/IR — Learn: No active exploitation campaign, IOCs, or ATT&CK-mappable TTPs are provided; this is a research enumeration finding. File as context for what attackers can target on internet-facing server management planes, but there is nothing actionable to hunt or detect today.
- Leader — Learn: A research finding showing widespread internet exposure of server management interfaces — useful benchmark data for a future board deck on infrastructure hygiene, but no breach, vendor incident, or regulatory trigger requires leadership action now.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.