Hardware Nightmare: 24,000 Data Center Servers Found Leaking Master Passwords to the Web

Hardware Nightmare: 24,000 Data Center Servers Found Leaking Master Passwords to the Web · Avonetics
A massive security discovery has laid bare a terrifying vulnerability hiding inside the physical bedrock of the internet.
Security researchers conducting a global scan of internet infrastructure discovered over 36,000 Baseboard Management Controllers exposed directly to the public web. More alarmingly, over 24,000 of those systems were actively leaking password-derived authentication hashes to anyone who asked.
Read nextExecutive Wi-Fi Mandate Triggers Enterprise Security Standoff Over iPhone Authentication
A Baseboard Management Controller, or BMC, is a tiny, independent computer built directly onto enterprise server motherboards. Designed to give system administrators remote power over physical hardware, a BMC operates completely below the server's main operating system. From a BMC interface, an administrator—or a hacker—can reboot machines, reinstall operating systems, flash malicious firmware, and access raw memory contents.
When these interfaces are exposed to the open web, they present the ultimate target for attackers seeking bare-metal access to enterprise networks.
The vulnerability stems from a legacy flaw in IPMI 2.0, a ubiquitous network protocol standardized over two decades ago. Under the specification, an endpoint is required to send a salted password hash back to any client attempting to connect before authenticating the user. Attackers can simply request the hash and crack it offline on high-powered GPU rigs without ever risking an account lockout.
During the audit, researchers discovered that over 30 percent of the harvested hashes could be cracked almost instantly using simple dictionary attacks or predictable factory password formulas. The exposure swept across modern hardware built by Supermicro and HPE, impacting critical systems operated by high-performance GPU cloud providers and corporate data centers.
Even classic factory defaults—including Dell's notorious legacy password 'calvin'—were found sitting active on bare-metal hardware exposed to the open web.
Your brand, right here.Reach story-obsessed listeners in 45+ languages → advertise on AvoneticsThe discovery ignited a fiery debate within the cybersecurity community.
One security specialist noted that exposing raw hardware management interfaces directly to the public internet is an unforgivable breach of basic IT hygiene, stating that responsibility falls squarely on irresponsible system administrators. Another analyst warned that relying on unique factory passwords is an illusion when protocol flaws leak hashes for offline cracking, rendering standard default protections completely useless.
However, skeptics argued that the researchers were overstating the apocalypse for publicity. One observer mocked the report as alarmist, characterizing the headline as sensationalized self-promotion for a new security tool. Others pointed out that properly managed infrastructure places hardware management interfaces behind strict IP whitelisting rules or private virtual networks, meaning the actual blast radius is far smaller than the raw numbers suggest.
Despite the pushback, the reality remains stark: tens of thousands of critical bare-metal servers were caught broadcasting master credentials to the dark corners of the web.
On the latest episode of System Error, our hosts break down the mechanics of this bare-metal meltdown, debating whether this exposure represents a systemic IT crisis or just another overhyped headline.