Over 917,000 IPMI Management Controllers Found Exposed on Public Networks
A ZoomEye scan conducted on 23 September 2026 using the query for port 623 identified 917,080 hosts with exposed IPMI-based out-of-band management controllers reachable from untrusted networks. These controllers, used by administrators for remote power control, console access, and firmware updates, operate independently of the host operating system, making them a high-value target for attackers. A threat actor who gains access to such a controller can power down systems, boot alternative images, or reflash firmware without any visibility from the OS. Security experts note that management controllers rarely appear in standard security reviews, as they are often managed by hardware or facilities teams rather than security functions. Recommended mitigations include isolating controllers on dedicated management networks, changing vendor default credentials, and keeping controller firmware updated alongside regular OS patch cycles.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in