← Back to Feed

Thousands of Data Center Controllers Open to Takeover

July 28, 2026 · Dark Reading · Severity: MEDIUM

Thousands of remote hardware management processors, such as IPMI, iDRAC, iLO, and BMC interfaces used to manage data center infrastructure, are exposed directly to the internet without adequate access controls. These out-of-band management controllers provide full keyboard-video-mouse access to servers, allowing anyone who compromises them to power cycle systems, mount ISO images, access console output, and effectively take complete control of the underlying hardware. The widespread exposure — often resulting from misconfigured network segmentation or defaults on vendor hardware — transforms what should be an administrative backchannel into a massive attack surface.

Key Takeaways

  • Thousands of remote hardware management processors (IPMI, iDRAC, iLO, BMCs) are internet-exposed and vulnerable to takeover.
  • These controllers provide full out-of-band server access including power control, console access, and ISO mounting.
  • Compromise of a management processor gives attackers complete hardware-level control, bypassing OS security controls.
☕ Buy a Coffee