Skip to content

Over 24,000 Exposed Server BMCs Leak Password Hashes via 20-Year-Old Vulnerability

At a glance: 24,000+ exposed servers leak authentication hashes via a 20-year-old BMC vulnerability, potentially enabling infrastructure takeover.

More than 24,000 publicly accessible servers are affected by a two-decade-old vulnerability in their Baseboard Management Controller (BMC) interface, leaking authentication password hashes. These BMC systems enable remote access to physical server functions and are frequent targets of attackers.

Security researchers have identified over 24,000 servers on the internet that expose authentication password hashes through their Baseboard Management Controllers (BMCs). The vulnerability has existed for approximately 20 years in BMC interfaces from various manufacturers.

BMCs are specialized management interfaces on server motherboards that allow administrators to monitor and control hardware functions independently of the operating system — including remote access. A successful compromise enables attackers to gain complete control over the physical infrastructure, regardless of operating system security measures.

The public accessibility of these BMC interfaces is critical, as they are normally supposed to be operated in trusted networks. The fact that password hashes are being exposed enables attackers to conduct offline brute-force attacks. With weak or older hashing methods, these attacks can be successful.

For CISOs, this means an immediate inventory task: all BMC systems in their own infrastructure must be checked for network accessibility. Particularly relevant are older server generations, as the vulnerability has been known for years and patches should be available.


Source: www.bleepingcomputer.com · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: