www.darkreading.com/cyber-ris…
Approximately 24,000 internet-exposed Baseboard Management Controllers (BMCs) remain vulnerable to a more than 20-year-old authentication flaw that allows attackers to crack credentials and gain privileged access to the underlying servers.
Because BMCs operate independently of the host operating system, kernel, containers, and workloads, the vulnerability is largely invisible to conventional security tools. Researchers at Lava found evidence that the issue has already been exploited in the wild.