Researchers report that many internet-facing Baseboard Management Controllers (BMCs) expose the IPMI (Intelligent Platform Management Interface) service in a way that discloses password-derived authentication hashes before an attacker completes login. According to the reporting, the issue affects systems reachable over UDP port 623, where an attacker can trigger part of the IPMI 2.0 authentication handshake and receive a password hash “challenge” or equivalent value prior to authentication.

The findings describe how BMCs operate outside the host operating system: they manage functions such as power cycling, mounting virtual media, providing a remote console, and flashing firmware. Because the BMC sits below the OS, host-level security monitoring may not detect exploitation at the management-controller layer.

One report states the scale as at least 36,872 internet-exposed IPMI interfaces observed, with 24,650 identified as disclosing authentication hashes before login. The reports characterize the behavior as a problem in the IPMI authentication flow rather than a specific vendor application, and they urge organizations to reduce exposure of BMC interfaces to the public internet and review IPMI configuration and access controls.