logo

Update: Another IPMI Mishap? Researcher Claims Supermicro Devices Vulnerable

ID: 18503e11-44c8-5569-bf8f-c21946906d7c

STIX ID: report--18503e11-44c8-5569-bf8f-c21946906d7c

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2014-06-21

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

A researcher found that Supermicro BMCs running IPMI store a plaintext password file (PSBlock) that can be downloaded from UPnP-enabled devices on port 49152; scans identified roughly 31,964 systems exposing these credentials. Although Supermicro released a firmware fix, many organizations have not updated BMC firmware, leaving widespread risk of unauthorized BMC access and potential full server compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.