Skip to content

24,650 Servers Exposed by Known IPMI Vulnerability

The Bottom Line: A two-decade-old IPMI flaw exposes tens of thousands of servers to remote takeover and remains unpatched across many organizations despite public documentation.

A vulnerability embedded in the IPMI protocol since 2004, publicly known since 2013, currently exposes over 24,650 servers to remote access. The flaw remains widely unpatched despite years of public awareness.

The Intelligent Platform Management Interface (IPMI) is a standard remote management protocol for server hardware. The affected vulnerability has existed since the 2004 IPMI specification and was publicly documented in 2013. It enables attackers to access remote management functions without authentication, thereby gaining administrative control over affected servers.

For a CISO, this constellation is critical for several reasons: First, this is a hardware management access (out-of-band) that operates parallel to the operating system and is often overlooked in monitoring and patch management. Second, the vulnerability’s years of public knowledge are no guarantee of patch rates – as the figures show, tens of thousands of devices remain vulnerable. Third, IPMI access can alter a server’s physical state, delete data, or restart operating systems without leaving traces in operating system logs.

The consequence for infrastructure management: hardware inventories must be explicitly checked for IPMI access, available patches for the respective manufacturers must be applied, and – ideally – IPMI access should be restricted at the network level to trusted administrative networks. The mere assumption that critical hardware is automatically maintained is insufficient.


Source: www.heise.de · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: