Update: Another IPMI Mishap? Researcher Claims Supermicro Devices Vulnerable
ID: 18503e11-44c8-5569-bf8f-c21946906d7c
STIX ID: report--18503e11-44c8-5569-bf8f-c21946906d7c
Feed Name: Security Ledger
Threat Score
A researcher found that Supermicro BMCs running IPMI store a plaintext password file (PSBlock) that can be downloaded from UPnP-enabled devices on port 49152; scans identified roughly 31,964 systems exposing these credentials. Although Supermicro released a firmware fix, many organizations have not updated BMC firmware, leaving widespread risk of unauthorized BMC access and potential full server compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
