The Raritan Blog

University of Michigan Team Publishes Paper on BMC/IPMI Security Issues

Richard Dominach
September 6, 2013

Security LockA University of Michigan team has published their research on IPMI and BMC security issues.  Entitled “Illuminating the Security Issues Surrounding Lights-Out Server Management,” this article follows up on the IPMI/BMC security issues highlighted by Dan Farmer and HD Moore as summarized in my previous blog on this subject. The Department of Homeland Security’s US-CERT team has posted an alert on the IPMI security risks.

The researchers provide an introduction to the issues, note the previous research, define IPMI/BMC security risks and analyze a particular implementation and describe their successful attack on this implementation.  They found “blatant textbook vulnerabilities” and concluded that the implementations “suggest either incompetence or indifference towards customer security.”  They then determine the number of publicly (Internet) accessible IPMI devices, which they determine to be more than 105,000.  They provide some defenses and lessons and indicate areas for future work.  The Washington Post has published an article on the paper and interviewed one of the authors, who criticizes the embedded device community for their security practices.

Customers who make use of BMC and IPMI based remote management cards and systems need to be aware of these issues and take the proper steps to safeguard their implementations.  Given the severity of these issues, they should consider alternative remote management solutions such as KVM-over-IP switches, which can avoid most of these risks.


Subscribe


Upcoming Events

National Association of Broadcasters (NAB) Show
April 18 - 22  •  Las Vegas Convention Center - Las Vegas, NV
AFCOM Data Center World
April 20 - 23  •  Washington DC Convention Center - Washington, DC
CiscoLive 2026
May 31 – June 3  •  Mandalay Bay Convention Center - Las Vegas, NV
2026 OCP Global Summit
October 12 - 15  •  San Jose Convention Center - San Jose, CA
DCD Connect VA
November 3 – 4  •  Lansdown Resort - Leesburg, VA

View all Events

Latest Raritan News

Greater Choice, Scalability, Speed: Why Legrand is Doubling Down on Open Compute Project Innovations
Posted on October 3, 2025
Legrand Brings Greater Flexibility to Data Center Operators with New Intelligent Rack PDU Universal Input Option
Posted on February 26, 2025
Legrand Expands Full Suite of DX2 SmartSensors, Keeping Data Centers Ahead of Rack Power and Environmental Monitoring Challenges
Posted on December 18, 2024
Legrand Wins Back-to-Back Awards for Intelligent Rack Power Distribution Innovation
Posted on May 24, 2024
Legrand Certifications and Process Controls Provide Confidence in Information Security for Network-Connected Devices in Data-Related Applications
Posted on April 1, 2024

View all news