Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.

More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.

Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.