24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html

22 points · 3 comments · view on lemmy.world

3 Comments

Cyber@feddit.uk · 5 pts · 5d

To counter the risk, it's advised to block UDP port 623 at the network edge, rotate factory-issued passwords during provisioning, disable legacy or weak options such as IPMI 1.5, restrict BMC access to a dedicated private management network, and apply network access controls to ensure only approved administrative systems can reach BMC interfaces.

Seems even IPMI 2.0 won't fix this either

Keep your BMCs OoB...

kn33@lemmy.world · 4 pts · 5d

Fucking hell

f4f4f4f4f4f4f4f4@sopuli.xyz · 1 pts · 5d

Only the hashes? Supermicro must have upped their game. You used to be able to get them to spit out their IPMI passwords in plaintext.