The Bottom Line: Over 24,650 publicly accessible server management interfaces expose IPMI authentication hashes, making them vulnerable to offline attacks on administrative credentials.
Security researchers have identified over 36,000 Baseboard Management Controllers (BMCs) that expose the IPMI protocol to the public Internet. In 24,650 of these systems, authentication hashes can be retrieved before login.
Cybersecurity researchers are warning of a critical configuration vulnerability in Baseboard Management Controller (BMC) management interfaces. The investigation identified a total of 36,872 BMC management interfaces on the Internet that make the Intelligent Platform Management Interface (IPMI) protocol publicly accessible. Of these systems, 24,650 disclose password-derived authentication hashes before successful login.
For CISOs, this vulnerability represents a significant attack risk: attackers can conduct offline attacks against the disclosed hashes. The IPMI protocol is typically used for out-of-band management of servers and provides remote access to hardware management functions. If the IPMI interface is exposed and discloses authentication hashes, this enables brute-force or dictionary attacks against server management credentials without network segmentation or access controls.
It is recommended not to expose IPMI interfaces to the public Internet. They should be restricted to private management networks and protected by firewall rules. Existing deployments should be reviewed for IPMI enablement and, if possible, disabled or moved to logically isolated management networks.
Source: thehackernews.com · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.