Nearly 90% of Data Center Building Management Systems Use Insecure Protocols, Claroty Finds

0
1

Key Takeaways

  • More than 40 % of power distribution units (PDUs) and roughly 30 % of HVAC/cooling assets are either directly exposed to the public internet or just one network hop away from an exposed system.
  • Across 750 k data‑center assets analyzed, 18 % sit one hop away from internet‑facing devices, creating indirect pathways for attackers.
  • Building management systems (BMS) are the weakest link: 88 % communicate over insecure protocols and 40 % run outdated firmware, despite few being directly internet‑exposed.
  • PDUs represent the highest‑risk category, with 41 % of devices one hop away from exposure, enabling attackers to cycle power or shut down server racks.
  • About one‑third of HVAC/cooling systems are similarly one hop away, threatening the nearly‑50 % of data‑center electricity they consume.
  • Power monitoring and UPS devices contain the greatest concentration of known exploitable vulnerabilities (KEVs): 82 % of power monitors use insecure protocols (mainly MODBUS) and 59 % have outdated firmware; 86 % of UPS units run insecure protocols, though only 23 % have outdated firmware.
  • IoT and smart‑sensor devices add further risk—nearly a quarter harbor KEVs and 72 % communicate over insecure protocols, often lacking the processing power for encryption or firmware updates.
  • Once inside, attackers can pivot to OT control systems, trigger KEV exploits, and knock a facility offline without ever touching a server, causing cascading service interruptions and potential physical damage.

Overview of Claroty’s Findings
Claroty’s Team82 research reveals a striking exposure gap in modern data‑center infrastructure. By scanning 750 000 assets, the team found that while only 0.4 % of devices sit directly on the public internet, a substantial 18 % are merely one network hop away from those exposed systems. This “one‑hop” proximity creates a hidden attack surface that can be leveraged to reach critical operational technology (OT) components such as power distribution units, HVAC controllers, and building management systems. The report stresses that any disruption to these systems can cascade, leading to widespread and costly service interruptions that affect not just the data center but also the facility itself but also the services it supports.


Scope and Methodology of the Study
The analysis encompassed a broad swath of data‑center infrastructure, including power monitoring units, uninterruptible power supplies (UPS), power distribution units (PDUs), HVAC and cooling systems, building management systems, and various IoT/smart‑sensor devices. Claroty employed passive network scanning and asset inventory techniques to map connectivity, identify protocols in use, and assess firmware versions. By classifying assets as “directly exposed,” “one hop away,” or “isolated,” the researchers could quantify how easily an adversary might traverse from an internet‑facing point to essential OT layers. The dataset’s size—750 000 assets—provides a statistically robust view of prevailing hygiene across the industry.


The IT/OT Convergence Landscape
Modern data centers increasingly blend information technology (IT) with operational technology (OT) to gain efficiency, automation, and visibility. Building management systems, power controls, and environmental sensors are now linked to enterprise applications and cloud‑based platforms. While this convergence enables real‑time monitoring and predictive maintenance, it also erodes the traditional air‑gap that once kept OT environments insulated from cyber threats. Each new integration point—whether a third‑party remote‑access tool, a management service, or a trusted network relationship—creates a potential conduit for attackers to move from the IT periphery into the OT core.


Exposure Metrics: Direct and One‑Hop Risks
The report’s headline numbers illustrate the scale of indirect risk. More than 40 % of PDUs and just over 30 % of HVAC/cooling assets are either directly reachable from the internet or sit one hop away from such exposure. Although the fraction of devices with a direct internet face is tiny (0.4 %), the one‑hop metric jumps to 18 % across the entire asset set. This disparity highlights that even modestly exposed IT components can serve as stepping stones to critical OT gear, amplifying the attack surface far beyond what a simple perimeter scan would suggest.


Building Management Systems: Weak Protocols and Firmware
Building management systems emerged as a particular concern. Despite only a small percentage being directly internet‑connected, 88 % of BMS devices communicated over insecure protocols, and 40 % operated with outdated firmware. Notably, more than 40 % of the surveyed BMS relied on BACnet implementations lacking authentication and encryption. Because a BMS offers a centralized view of temperature, power, humidity, and access controls, an attacker who gains access can manipulate environmental conditions, trigger shutdowns, or cause physical damage to hardware—a “lethal tool” capable of disrupting an entire facility without needing to breach server racks directly.


Power Distribution Units: Highest‑Risk Assets
Power distribution units (PDUs) topped the risk list, with 41 % of devices positioned one hop away from an internet‑exposed system. PDUs are responsible for delivering power to individual server racks; compromising them allows an adversary to cycle power, shut down specific racks, or induce systemic hardware damage across thousands of customer workloads. The report warns that an attacker who penetrates the outer network perimeter can pivot into the PDU layer and execute precise, destructive actions that would instantly knock out services, illustrating why PDUs merit prioritized hardening.


HVAC and Cooling Systems: Substantial Exposure
Heating, ventilation, and air‑conditioning (HVAC) systems, which consume close to half of a data center’s electricity, also show considerable vulnerability. Roughly one‑third of these assets are one hop away from an exposed system, meaning that an attacker could disrupt cooling, leading to overheating, throttling, or forced shutdowns of IT equipment. Given the critical role of temperature stability in maintaining hardware reliability, any compromise of HVAC controls can rapidly degrade performance and increase the risk of permanent damage.


Power Monitoring and UPS: Concentration of Known Exploitable Vulnerabilities
The study found that power monitoring devices and uninterruptible power supplies harbor the highest density of known exploitable vulnerabilities (KEVs). Specifically, 82 % of power monitoring units use insecure protocols—predominantly MODBUS—while 59 % run outdated firmware. For UPS units, the numbers are slightly different but still alarming: 86 % communicate over insecure protocols, yet only 23 % have outdated firmware. Because these devices manage the flow and quality of electrical power, exploiting a KEV here could allow an attacker to induce power fluctuations, trigger false overload trips, or disable backup power, effectively cutting off the data center without ever touching a server.


IoT and Smart Sensors: Emerging Threat Vectors
IoT and smart‑sensor components, increasingly deployed for granular environmental monitoring, add another layer of risk. Nearly a quarter of these devices contain KEVs, and 72 % transmit data over insecure protocols. Many of these sensors lack the computational resources to support strong encryption or to accept firmware updates, making them persistent weak points. An attacker who compromises a sensor can use it as a foothold to laterally move into more critical OT networks, amplifying the overall risk posture of the facility.


Potential Attack Scenarios and Cascading Impacts
Once inside the OT environment, attackers can leap from compromised device‑Vulnerabilities
Once an attacker gains a foothold—whether through a vulnerable BMS, an exposed PDU, or an insecure sensor—they can move laterally to OT control systems that gather data from sensors and actuators. These systems are often subject to known exploitable vulnerabilities; exploiting them enables the adversary to shut down control loops, halt physical processes, or issue malicious commands that damage hardware. Because many of these OT devices are unpatched KEV holders, a single exploit can cascade: a power‑distribution manipulation can trigger overheating, which then forces HVAC overloads, ultimately leading to server throttling or shutdown. The report emphasizes that such attacks can knock a data center offline without the need to breach any server directly, underscoring the importance of securing the underlying infrastructure.


Recommendations and Mitigation Strategies
While the excerpt focuses on findings, the implied mitigations are clear. Organizations should enforce network segmentation to isolate critical OT assets from internet‑facing IT systems, thereby increasing the number of hops required for an attacker to reach them. Deploying strong authentication and encryption on protocols such as BACnet, MODBUS, and proprietary management interfaces is essential. Regular firmware patching—especially for power monitoring, UPS, and PDU units—must be prioritized, and asset inventories should be continuously updated to detect outdated or unsupported devices. Finally, adopting a zero‑trust approach for remote access, monitoring for anomalous lateral movement, and conducting regular red‑team exercises can help detect and mitigate threats before they cause cascading failures.


This summary distills the core insights from Claroty’s Team82 report on data‑center OT exposure, highlighting where the greatest risks lie and why securing power, cooling, and building‑management infrastructure is vital to maintaining uninterrupted service.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here