HackMyIP
← Back to News
2026-07-28 Dark Reading

Thousands of Exposed Data Center BMCs Vulnerable to Password Cracking

VulnerabilityAuthenticationThreat Intel

Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and threat actors have already begun weaponizing the flaw to seize administrative control of enterprise server fleets.

Researchers have identified upwards of 50,000 Remote Management Controllers — sold under names such as Dell iDRAC, HPE iLO, Lenovo XClarity, and Supermicro IPMI — reachable directly from the public internet. These out-of-band processors authenticate administrators using IPMI 2.0's RAKP message-exchange protocol, which transmits the password hash in response to an attacker-supplied challenge. A single captured handshake is enough to feed the hash into high-throughput offline brute-force or dictionary attacks on commodity GPU rigs, and many of the affected devices still ship with default manufacturer credentials never rotated by the operator. Censys, Team Cymru, and independent honeypot operators have observed continuous scanning and active exploitation of these endpoints at internet scale.

Successful authentication yields near-total hardware control. An attacker can power-cycle hosts, mount remote virtual media, exfiltrate firmware and TPM-resident keys, and flash a persistent implant directly into the BMC SPI flash. Because the compromise lives below the operating system layer, re-imaging the disk or reinstalling the OS will not evict the intruder — the malware survives in a region typically invisible to host-based endpoint protection. From a compromised BMC, adversaries can also pivot into the management VLAN and laterally reach sibling servers that were never directly internet-exposed.

Defenders should immediately run the hackmyip.com port scanner against their external perimeter to flag any reachable UDP/623 or TCP/5900 management endpoints, audit every administrator credential with the password strength checker, and verify that the management web UI is terminated behind a properly issued certificate using the SSL/TLS checker. Beyond detection, organizations must enforce network segmentation that confines BMC, iDRAC, and iLO interfaces to dedicated out-of-band management VLANs accessible only via hardened jump hosts, apply the latest vendor firmware patches, disable IPMI-over-LAN where remote lights-out access is not strictly required, and rotate every default manufacturer password before the box goes into production.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →