GPU Acceleration Exposes Password Risks Across 24,000 Servers
The Intelligent Platform Management Interface, or IPMI, is a legacy protocol widely used to administer servers through their baseboard management controllers, independently of the operating system. That privileged access makes an internet-exposed BMC a valuable target, while multi-GPU systems have sharply reduced the time and cost needed to test password hashes offline. The risk is particularly acute for hardware that still relies on fixed factory credentials, which can give attackers broad control if recovered.
Security researchers found that more than 24,000 server BMC interfaces worldwide return authentication material before a user logs in, allowing attackers to capture the data and attempt password recovery offline. High-performance systems equipped with multiple GPUs can crack fixed factory passwords in a short period, magnifying a weakness in the aging IPMI design. Experts urged operators to block the relevant ports from public access, restrict management interfaces to trusted networks and replace default passwords immediately.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.