SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Researchers find 36,872 exposed server management interfaces

Researchers find 36,872 exposed server management interfaces

Wed, 29th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Lava researchers found more than 36,000 internet-exposed server management interfaces used across enterprise, cloud and AI data centre infrastructure.

The research focused on Baseboard Management Controllers, or BMCs, dedicated management processors that handle tasks such as power control, firmware management, remote console access, operating system installation and system recovery. Because they operate independently of the main operating system, a compromised BMC can give an attacker a route into a server that sits outside many standard security tools.

Lava identified 36,872 internet-facing BMCs. Nearly 25,000 of them exposed password-derived authentication material before login, potentially allowing attackers to recover credentials offline instead of relying on repeated online login attempts.

According to the findings, the weakness stems from the IPMI management protocol, a longstanding technology used for remote server administration. Modern graphics processing hardware has also made the issue easier to exploit in practice, as attackers can use that computing power to crack passwords far faster than in the past.

Researchers said the problem extends beyond weak or reused passwords. Even unique factory-issued passwords could be recovered offline because their formats were predictable enough to narrow the search process for password-cracking systems.

That finding challenges an assumption held by some operators that individually assigned default credentials provide enough protection if the management interface remains exposed to the public internet. Here, the issue lies in the way the protocol exposes password-derived material remotely.

The work included validation on systems from two major server manufacturers. Lava said HPE iLO factory passwords were recoverable in under one minute using modern GPU hardware, while Supermicro factory passwords were recoverable in about one hour despite being uniquely assigned to each server.

The affected systems included infrastructure run by large enterprises and cloud providers, according to the researchers. New internet-exposed BMCs also continued to appear during the study, suggesting the issue is widespread rather than limited to a small number of poorly configured machines.

Active exploitation

Beyond the technical weakness, the researchers said they found signs that attackers are already using exposed BMCs in the field. Those signs included ransomware operators leaving extortion notes on exposed interfaces, indicating the systems are more than a theoretical target.

That raises concern for AI data centres in particular, where multiple tenants may rely on the same bare-metal infrastructure. If a single management controller is compromised in that environment, attackers could gain an opportunity to move across shared systems or reach workloads belonging to more than one organisation.

"Organisations have spent years hardening cloud workloads and operating systems, but many have overlooked the infrastructure that sits beneath them," said Yakir Kadkoda, Chief Technology Officer and Co-Founder, Lava.

"These management controllers hold the keys to servers and data centers. Once compromised, attackers can operate below the visibility of almost any security tools, maintain persistence even after systems are rebuilt, and potentially move deeper into critical infrastructure. As AI infrastructure rapidly expands, securing this layer has become far more urgent," said Kadkoda.

Mitigation steps

Lava said the issue cannot be fixed simply by setting stronger passwords if the legacy protocol remains available on an internet-exposed interface. Researchers recommended removing BMC management interfaces from direct public internet exposure, isolating them on dedicated management networks, rotating factory credentials during deployment and disabling legacy IPMI functions where possible.

Lava said it notified affected vendors and operators it could identify as part of its disclosure process. According to the company, Supermicro acknowledged the findings and said it would evaluate stronger default password policies for future systems.

The findings point to a persistent weakness in a layer of infrastructure many security teams may not monitor closely. Unlike software inside a virtual machine or operating system, BMCs control fundamental server functions and can remain accessible even after the rest of a system has been rebuilt.

For cloud operators, enterprises and companies building AI computing estates, that leaves a security problem at the hardware management layer rather than the application layer. Researchers said exposed BMCs can provide a route for persistent access with little visibility to endpoint security tools, making them an attractive target for attackers seeking durable control.

Of the 36,872 internet-facing systems Lava identified, almost 25,000 exposed password-derived data before login, underscoring how widely the underlying protocol issue still appears across connected server infrastructure.