thehackernews.com 7/28/2026, 3:49:13 PM · external

Thousands of Exposed Server BMCs Leak IPMI Hashes Before Login

Thousands of Exposed Server BMCs Leak IPMI Hashes Before Login
CyberSIXT Evidence Panel Source marked as original reporting

THE article highlights a critical cybersecurity vulnerability involving 24,650 Internet-exposed Baseboard Management Controllers (BMCs) that are disclosing IPMI password hashes prior to user login. This exposure poses significant risks to server security, allowing potential attackers to gain unauthorized access to sensitive systems. Recommendations for mitigating this vulnerability include implementing stronger access controls and regularly monitoring BMC configurations to prevent exploitation.

View full article

Article by CyberSIXT