Thousands Of Internet Facing IPMI Interfaces Expose Password Hashes Through Known Flaw
Researchers found more than 24,650 internet exposed BMCs disclosing IPMI password hashes before login because of a long standing specification flaw, increasing the risk of offline password cracking attacks.