917,169 Matches on Port 623 and 109,327 on app="IPMI": Two Views of the Out-of-Band Layer
Baseboard management controllers are the machines that watch the other machines. Two ZoomEye queries measuring that layer returned very different numbers, and the gap explains more about the technology than either figure alone.
The measurement
Both queries ran on 25 September 2026 with sub_type=all and pagesize 1. The query port="623", the IPMI network port, returned 917,169 matches. The query app="IPMI" returned 109,327 matches.
Why the two numbers diverge
Port 623 is a protocol assignment, and anything bound to it produces a match. That includes BMCs, but also virtual management interfaces, test services, and hosts where port 623 is answered by something that is not a management controller at all.
An application fingerprint is a stronger claim: it means the scanner observed enough of a response to attribute the service to the IPMI family. The smaller number is therefore closer to a population of actual management interfaces, and the larger number is closer to a population of addresses that answer on the management port.
Neither is a count of unauthenticated management access. The relevant question for both is whether the interface requires credentials and whether it is reachable from a network that should not have it.
Why the out-of-band layer deserves attention
A BMC has privileges the operating system does not. It can present virtual media, capture the console, power-cycle the host, and read the hardware inventory. It typically has its own credentials, its own firmware cadence, and its own network configuration, and it is very often managed by a different team than the server it belongs to.
That combination is what makes the layer worth measuring at all. CVE-2026-85508, published on 4 September 2026, is a stack-based buffer overflow in the freeipmi ipmi-oem tool with a CVSS score of 9.8, affecting the parsing of Dell system information responses. It is a client-side flaw rather than a BMC flaw, and it makes the same point from the other direction: the management path is a software surface at both ends.
Reading the two counts together
The useful conclusion is not that one number is right and the other is wrong. It is that a port measurement and a product measurement answer different questions, and the gap between them is the uncertainty.
In practice, assume the port total overstates the management-controller population and the fingerprint total understates it, because IPMI implementations do not always identify themselves in a way a scanner can attribute. Plan using the range, not a single figure.
What to do about it
Inventory the management controllers separately from the servers. Every BMC should have its own entry, its own owner, and its own patch state, and in most organisations it has none of the three.
Move management traffic onto a dedicated network that cannot initiate connections inward, and change the default credentials that shipped with the hardware.
Finally, monitor authentication against the management interfaces. A BMC that receives login attempts from an unexpected source is an event that most logging stacks never see, because the controllers are outside the systems that send logs.
References
- ZoomEye search for port="623": https://www.zoomeye.ai/
- ZoomEye search for app="IPMI": https://www.zoomeye.ai/
- NVD record for CVE-2026-85508: https://nvd.nist.gov/vuln/detail/CVE-2026-85508
Top comments (0)