# Legacy Flaw Exposes Over 24,000 BMC Interfaces to Password Hash Leaks

*Published July 29, 2026*
*Source: [https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/](https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/)*

## Executive Summary

Researchers have discovered that over 24,000 BMC and IPMI interfaces are leaking password hashes due to a decades-old flaw, making them vulnerable to offline attacks. This exposure poses a significant risk to organizations, especially those in critical sectors, necessitating immediate security measures.

## Article

A recent discovery by cybersecurity researchers has revealed a significant vulnerability in server Baseboard Management Controllers (BMCs). The flaw, which has been present for decades, affects 24,650 internet-exposed BMC and IPMI interfaces. These interfaces, typically used for remote server management, are inadvertently disclosing password-derived hashes before users even log in. This exposure allows attackers to potentially crack these hashes offline, posing a significant threat to the affected systems.

The issue lies in the inherent design of these interfaces, which were not originally built with modern cybersecurity threats in mind. As a result, they leak sensitive information that can be exploited by malicious actors. Organizations using these vulnerable BMCs are at risk of unauthorized access, data breaches, and potential system compromises. The impact is particularly concerning for industries reliant on robust IT infrastructure, such as finance, healthcare, and government sectors.

To mitigate the risk, organizations should immediately assess their systems for exposed BMC interfaces and apply necessary security patches or updates. Network segmentation and robust password policies can further reduce the potential for exploitation. Regular security audits and the implementation of intrusion detection systems are also recommended to identify and address vulnerabilities before they can be exploited by cybercriminals.
