IPMI/BMC Security Vulnerability in Older Implementations

From Thomas-Krenn-Wiki
Jump to navigation Jump to search

Introduction

In July 2025, attention was once again drawn to a vulnerability that has been known for many years in various implementations of the Intelligent Platform Management Interface (IPMI) and the underlying Baseboard Management Controllers (BMCs). Security researchers have identified numerous management interfaces that are available via Internet, which remain vulnerable to an attack on the authentication mechanism.

The vulnerability allows, with certain requirements, to read out password hashes from user accounts. After that, they can be analyzed offline or attacked via brute force or dictionary attacks. As IPMI operates independently of the installed operating system and provides extensive administrative functions, a successful compromise poses a significant security risk.

Background

IPMI is a standardized management interface for administrating servers. The implementation is made via Baseboard Management Controller (BMC), which operates independently from the operating system. Administrators can also

  • switch on and switch off servers
  • monitor the system condition
  • update firmware
  • perform console access as well as
  • remote installations

As these functions are also available when the operating system is switched off or does not function, the BMC possesses multiple authorizations and should be extra protected.

Description of vulnerability

The affected vulnerability concerns the authentication mechanism, which are older than IMPI-2.0 implementations. An attacker can send special prepared authentication requests and can therefore receive hash values from user passwords without successful authentication.

Next, the hash values can be analyzed offline. Depending on the password quality, an attacker could use this to determine the actual login data. After successful login, the attacker gets access to all management functions of the BMC.

The vulnerability itself does not allow direct access to the operating system, but it can allow the complete remote access to the server.

Affected systems

In general, servers whose BMC firmware implements the vulnerable authentication mechanism and whose IPMI interface is accessible from untrusted networks may be affected.

The following are particularly relevant:

  • older server platforms
  • not updated BMC firmware
  • IPMI interfaces accessible from the public network
  • systems with weak or reused passwords

Whether a specific system is affected depends on the manufacturer, firmware version, and configuration.

Potential impact

A successful utilization may have the following consequences:

  • disclosure of password hashes
  • offline attacks on user passwords
  • complete access on the BMC
  • remote console access
  • turning systems on and off
  • integration of virtual installation medium
  • change of firmware configuration
  • bypassing Operating System Security Mechanisms

As the BMC operates independently of the host system, a lot of these opportunities remain in place even if the actual operating system is switched off.

Verification of the own infrastructure

Administrators should check

  • if IPMI interfaces are publicly available
  • which firmware version is used
  • if safety updates are available
  • which user accounts are available
  • if strong passwords should be used
  • which networks should have access to the BMC.

In addition, it is recommended to monitor the firewall rulesas well as the management networks on a regular basis.

Protective measures

The following measures are recommended to protect the system:

  • install latest BMC-firmware
  • make IPMI accessible exclusively via internal management networks
  • avoid public accessibility
  • use strong individual passwords
  • remove unused user accounts
  • replace standard passwords
  • restrict management accesses on confidential administrators
  • use VPN or Jump Hosts for the remote access, if possible

Firmware updates

Multiple server manufacturers provide updated firmware versions that fix known vulnerabilities or implement additional protective measures. The respective release notes should be controlled before an update and the update is performed in accordance with the manufacturer's recommendations.

Updates for Thomas-Krenn products

Updates on the corresponding system can be found in the Thomas-Krenn download area. The versions in the download area have been tested by us to guarantee the stability and compatiblity of our systems.

If you require the latest version for your system and it is not yet available in our download area, you can get it at the respective manufacturer.

Conclusion

The renewed attention for this vulnerability, that has been known for years, shows that management interfaces continue to be a frequently underestimated target for attacks. Independent from the age of the vulnerability, public available BMC or IPMI interfaces should be verified on a regular basis, operted with the latest firmware and available via secured management networks only.

Sources


Author: Thomas-Krenn.AG

At Thomas-Krenn.AG we pay attention to the best possible service. To do justice to this, we have created our Thomas-Krenn Wiki. Here we share our knowledge with you and inform you about basics and news from the IT world. You like our knowledge culture and want to become part of the team? Visit our job offers.

 

Translator: Alina Ranzinger

Alina has been working at Thomas-Krenn.AG since 2024. After her training as multilingual business assistant, she got her job as assistant of the Product Management and is responsible for the translation of texts and for the organisation of the department.


Related articles

AMD EPYC 7003 Milan
AMD EPYC Performance Tuning
Optimize memory performance of Intel Xeon Scalable systems