ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Decades-old BMC flaw leaks password hashes from 24,000 internet-facing servers

Source headline: Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

A long-standing vulnerability in some Baseboard Management Controller (BMC) interfaces can expose authentication password hashes. Security researchers observed more than 24,000 internet-facing servers returning leaked hash data. The issue stems from weak handling in the BMC authentication workflow, allowing attackers to obtain credentials for offline cracking. This increases the risk of account compromise and potential lateral movement within affected environments. Organizations should inventory exposed BMC services, restrict access to management networks, and apply vendor fixes or compensating controls.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#credential-compromise #bmc #internet-exposed #out-of-band-management #password-hash-leak
Original reporting BleepingComputer Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Open original source