Decades-old BMC flaw leaks password hashes from 24,000 internet-facing servers
Source headline: Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Intelligence Summary
A long-standing vulnerability in some Baseboard Management Controller (BMC) interfaces can expose authentication password hashes. Security researchers observed more than 24,000 internet-facing servers returning leaked hash data. The issue stems from weak handling in the BMC authentication workflow, allowing attackers to obtain credentials for offline cracking. This increases the risk of account compromise and potential lateral movement within affected environments. Organizations should inventory exposed BMC services, restrict access to management networks, and apply vendor fixes or compensating controls.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.