Baseboard Management Controllers and Organizations using BMCs with IPMI 2.0: 24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login

Baseboard Management Controllers and Organizations using BMCs with IPMI 2.0: 24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login

Critical IPMI 2.0 Flaw Exposes Thousands of Servers to Pre-Authentication Attacks

Security researchers have identified 36,872 internet-facing Baseboard Management Controllers (BMCs) running the IPMI 2.0 protocol, with 24,650 (67%) leaking password-derived authentication hashes before login. The flaw, rooted in IPMI 2.0’s 20-year-old specification, allows attackers to capture password hashes without credentials by simply initiating a connection.

The vulnerability stems from IPMI 2.0’s challenge-response mechanism, which transmits a password hash during the handshake prior to authentication. The hash uses a weak derivation method, making it susceptible to offline brute-force and dictionary attacks. Attackers can recover passwords in hours to days using commodity hardware, then gain full control of the server.

A compromised BMC provides out-of-band management access, including remote power control, virtual console access, and the ability to mount virtual media. Most critically, attackers can install persistent firmware backdoors that survive OS reinstallation, evading standard incident response measures like reimaging or credential rotation. Detection requires BMC firmware integrity checks, a practice rarely performed in most organizations.

The flaw has been publicly known for over a decade, yet its persistence across 24,650 exposed interfaces highlights a gap in remediation. Researchers report active scanning by attackers, increasing the risk of exploitation. Since the issue is protocol-level, no firmware patch can fully mitigate it network access restrictions (e.g., VPN-only access) remain the primary defense.

Source: https://dailysecurityreview.com/cyber-security/24650-internet-exposed-server-bmcs-leak-password-hashes-before-login/

Baseboard Management Controllers TPRM report: https://www.rankiteo.com/company/aspeed-technology

Organizations using BMCs with IPMI 2.0 TPRM report: https://www.rankiteo.com/company/bleepingcomputer

"id": "bleasp1785349499",
"linkid": "bleepingcomputer, aspeed-technology",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Global (internet-facing)',
                        'type': 'Servers with BMCs running IPMI 2.0'}],
 'attack_vector': 'Network-based pre-authentication hash leakage',
 'data_breach': {'sensitivity_of_data': 'High (password hashes enabling full '
                                        'server control)',
                 'type_of_data_compromised': 'Password-derived authentication '
                                             'hashes'},
 'description': 'Security researchers have identified 36,872 internet-facing '
                'Baseboard Management Controllers (BMCs) running the IPMI 2.0 '
                'protocol, with 24,650 (67%) leaking password-derived '
                'authentication hashes before login. The flaw allows attackers '
                'to capture password hashes without credentials by initiating '
                'a connection, enabling offline brute-force and dictionary '
                'attacks to recover passwords and gain full control of the '
                'server.',
 'impact': {'operational_impact': 'Full out-of-band management access, '
                                  'including remote power control, virtual '
                                  'console access, and persistent firmware '
                                  'backdoors',
            'systems_affected': '36,872 internet-facing BMCs (24,650 '
                                'vulnerable)'},
 'initial_access_broker': {'backdoors_established': 'Persistent firmware '
                                                    'backdoors (survive OS '
                                                    'reinstallation)'},
 'lessons_learned': 'The persistence of the IPMI 2.0 flaw highlights gaps in '
                    'remediation and the need for network-level protections. '
                    'Detection of BMC firmware backdoors is rarely performed, '
                    'increasing long-term risk.',
 'post_incident_analysis': {'corrective_actions': 'Network access '
                                                  'restrictions, BMC firmware '
                                                  'integrity checks, and '
                                                  'enhanced monitoring for '
                                                  'exploitation attempts',
                            'root_causes': "Protocol-level flaw in IPMI 2.0's "
                                           'challenge-response mechanism (weak '
                                           'password hash derivation)'},
 'recommendations': 'Implement network access restrictions (e.g., VPN-only '
                    'access), perform BMC firmware integrity checks, and '
                    'monitor for active scanning/exploitation attempts.',
 'references': [{'source': 'Security researchers'}],
 'response': {'containment_measures': 'Network access restrictions (e.g., '
                                      'VPN-only access)',
              'remediation_measures': 'BMC firmware integrity checks (rarely '
                                      'performed)'},
 'title': 'Critical IPMI 2.0 Flaw Exposes Thousands of Servers to '
          'Pre-Authentication Attacks',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'IPMI 2.0 protocol flaw (weak challenge-response '
                            'mechanism)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.