BMC default credentials

BMCs ship with fixed default credentials, and they are changed far less often than OS or application passwords because the management controller lives on a separate network administrators consider private and forget about. The defaults are well known per vendor: root/calvin on Dell iDRAC, ADMIN/ADMIN on many Supermicro boards, Administrator with a per-device password on HPE iLO (sometimes printed on a pull-tab and left unchanged), and others. Trying these grants full administrative control of the controller, and therefore of the host's power, physical console, and virtual media, so a reachable BMC with default credentials is a complete server compromise.

bash
# identify the BMC vendor, then try its documented defaults over IPMI and the web UI
ipmitool -I lanplus -H <bmc> -U root -P calvin user list          # Dell iDRAC default
ipmitool -I lanplus -H <bmc> -U ADMIN -P ADMIN user list          # common Supermicro default
curl -sk https://<bmc>/ | grep -iE 'idrac|ilo|supermicro'         # fingerprint for the web UI

Exploitation notes#

  • Fingerprint the vendor first (web UI, IPMI device ID), then try that vendor's documented defaults; root/calvin (Dell), ADMIN/ADMIN (Supermicro) are the highest-yield.
  • The BMC being on a "private" management network is why defaults persist; once you reach that network (a flat segment, a jump host, a VLAN hop), defaults are the easiest path.
  • Default admin access yields power control, KVM console, and virtual media, enough to boot an attacker image and own the OS, see iDRAC and iLO.
  • Combine with RAKP hash disclosure (which often recovers exactly these default passwords) and cipher 0 where defaults were changed.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more