HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

24,650 Internet‑Exposed BMCs Leak IPMI Password Hashes Prior to Login

Security researchers discovered that 24,650 publicly reachable Baseboard Management Controllers expose password‑derived IPMI hashes before login, creating a credential‑theft vector. The finding highlights a configuration‑management gap that SOC 2 controls are built to detect and remediate, underscoring the need for continuous evidence collection.

LiveThreat™ Intelligence · 📅 July 29, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

24,650 Internet‑Exposed BMCs Leak IPMI Password Hashes Prior to Login

What Happened — Researchers scanning the public IPv4 space identified 36,872 server‑management interfaces that expose the Intelligent Platform Management Interface (IPMI) protocol. Of those, 24,650 Baseboard Management Controllers (BMCs) return password‑derived authentication hashes before a login attempt, effectively leaking credential material to any unauthenticated observer.

Why It Matters for Compliance & Audit Readiness

  • This is a classic control‑gap scenario that SOC 2’s CC6.1 – Configuration Management and CC7.1 – Logical Access Controls are designed to prevent and evidence.
  • Continuous monitoring of configuration drift and automated evidence collection can prove you’ve remedied the exposure before an audit.
  • Mapping this finding to your Trust Center demonstrates due‑diligence to auditors and customers alike.

Who Is Affected – Cloud‑infrastructure providers, data‑center operators, and any organization that runs on‑premise servers with BMC/IPMI management interfaces (e.g., finance, SaaS, telecom).

Recommended Actions

  • Inventory all BMC/IPMI endpoints and block external access at the network perimeter.
  • Apply vendor‑supplied firmware updates that harden IPMI authentication and disable hash disclosure.
  • Enable continuous configuration monitoring and log collection for BMC management traffic; map findings to SOC 2 CC6.1/CC7.1 controls.
  • Document remediation steps and retain evidence in a centralized Trust Center for audit readiness.

Technical Notes – The exposure stems from a default IPMI implementation that returns a salted SHA‑1 hash of the password during the “Get Device ID” command. No CVE is currently assigned; the issue is a misconfiguration rather than a software flaw. Affected data includes password hashes that can be cracked offline, leading to potential full BMC compromise. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →