BMC Hash Leaks Put Server Control Offline

BMC exposure is more dangerous than a bad login page because it leaks password-derived material before authentication, so attackers can crack the password offline without tripping repeated-failure alerts. Once they have a working BMC credential, they are below the OS and can control power, console access, virtual media, and firmware on the host. Lava found 36,872 internet-facing BMCs and 24,650 that returned HMAC-SHA1 authentication material before the client had authenticated. The dataset also showed many recoverable from public wordlists or factory-style passwords, including 2,340 endpoints where named accounts like ADMIN or root matched known passwords. That makes remote-management credentials part of the same trust boundary as VPN or cloud-console logins. If a BMC password is weak or default, host-based defenses do not matter until the management plane is cut off or the credential is changed.

Part of the PlainSec briefing for 2026-07-28

Sources