Illustration of an IPMI vulnerability exposing data center servers through insecure BMC management interfaces.

Security researchers have warned that a 20-year-old vulnerability in the Intelligent Platform Management Interface (IPMI) could allow attackers to compromise thousands of internet-exposed data center servers. The flaw affects Baseboard Management Controllers (BMCs), enabling attackers to capture authentication data and crack passwords offline without triggering security alerts.

Illustration of an IPMI vulnerability exposing data center servers through insecure BMC management interfaces.Illustration of an IPMI vulnerability exposing data center servers through insecure BMC management interfaces.

Researchers identified over 36,000 publicly accessible IPMI interfaces, with nearly 67% exposing password-derived authentication data. Weak or default credentials significantly increase the risk, allowing attackers to gain full control of servers, modify firmware, steal sensitive data, and establish persistent access that survives operating system reinstalls.

Organizations are urged to remove IPMI interfaces from the public internet, block UDP port 623, replace default BMC passwords, disable insecure authentication methods, and isolate management networks using VPNs and strict access controls to reduce the risk of compromise.

Strengthen your critical infrastructure with NPAV Endpoint Security (EPS)— advanced protection for enterprise servers and networks.