24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw
More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.
More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed in BMC firmware for over two decades. BleepingComputer counted the exposed units on July 28.
BMC stands for Baseboard Management Controller — a dedicated management processor embedded in enterprise and data center servers that runs independently of the host OS. Remote power cycling, out-of-band console, BIOS configuration, hardware health monitoring all route through the BMC. An attacker who takes the BMC controls the machine at a layer below the operating system.
The vulnerability causes the BMC to expose a credential hash during the authentication handshake. That hash is recoverable by an unauthenticated party on the network. It can be cracked offline. If the credential is weak or reused, the attacker gets full management access.
Scope: confirmed. Twenty-four thousand-plus internet-reachable BMC interfaces, authenticated exposure active. How many hashes have been extracted: unconfirmed. How many have been cracked and used: unconfirmed. Treat any internet-facing BMC as a compromised credential until proven otherwise.
Why 24,000 units are exposed. BMC management interfaces should never be reachable from the public internet. The recommendation — isolated out-of-band management VLAN, no route to production or public subnets — has existed as long as the flaw. These units are exposed because a shared network port was used for BMC access, a firewall rule was absent or got reset, or the configuration was never audited after hardware provisioning. This is not a new problem that appeared recently. It accumulated.
What to do
Audit:
- Inventory every BMC management interface in your environment. Check whether any are reachable from outside your management VLAN. A targeted scan of your own IP ranges or a Shodan search for your address space answers the question quickly.
- Any BMC confirmed internet-reachable: treat as fully compromised. The credential hash may have already been extracted.
Isolate:
- Move BMC management interfaces to a dedicated out-of-band management VLAN with no public route.
- If shared network interfaces are carrying BMC traffic, fix that. The segregated management network exists specifically to prevent this exposure class.
Rotate credentials:
- Change BMC credentials on every unit that was or may have been internet-accessible.
- Rotate any credentials that were shared with or reused from an exposed BMC interface.
Firmware:
- Check your hardware vendor’s current BMC firmware and apply available updates. Firmware patches do not substitute for network isolation — do both.
Priority call: audit now if you operate servers in colocation or any environment where BMC management interfaces have not been explicitly inventoried and confirmed off the public internet. The flaw is old. Credential hashes are usable immediately after capture. Network isolation closes the window. Rotation limits damage from hashes already taken.
Source: BleepingComputer.
Found this useful? Share it.


