Thursday, 6 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 6 August 2026 at 02:52

Thousands of servers can be backdoored via vulnerable motherboard controllers

Research reveals that numerous servers from top manufacturers remain exposed to remote attacks due to critical flaws in baseboard management controllers, allowing hackers deep access to data centers.

Foto: Ars Technica

Research presented Wednesday at the Black Hat security conference in Las Vegas shows that thousands of Internet-connected servers from major manufacturers can be remotely compromised through vulnerabilities in baseboard management controllers (BMCs). BMCs are miniature computers embedded in virtually every enterprise server motherboard. They run their own firmware, network stack, and IP address, enabling administrators to monitor hardware status, reboot machines, install updates, or even reinstall operating systems. They operate even when the host server is turned off or unresponsive, providing “lights out” and “out-of-band” management.

Security researcher HD Moore, CEO and founder of runZero, has uncovered more than a dozen new vulnerabilities in BMCs from HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. He also found that some weaknesses he highlighted in 2013 remain unpatched.

Moore conducted two large-scale scans. The external scan found over 86,000 BMCs exposing management services to the public Internet. More than 54% of these devices contained at least one critical vulnerability. As many as 75,000 remained vulnerable to CVE-2013-4786, an IPMI 2.0 authentication flaw enabling offline password cracking. An internal scan of 126,761 BMCs found nearly 29% had one or more critical vulnerabilities.

The identified bug classes include flaws in the IPMI authentication handshake, failure to enforce integrity and encryption in-session, predictable session identifiers, pre-authentication memory corruption, unsigned firmware, recoverable secrets, and weak default credentials. Affected vendors include HPE, Supermicro, OpenBMC, H3C, Nvidia, Intel, Huawei, Dell, and others.

Moore released an open-source tool called OOBscan to help administrators detect vulnerabilities in their server fleets. He advises setting long, unique usernames and complex passwords, disabling IPMI and KCS where possible, and isolating each BMC network interface.

Moore noted that BMCs remain an underrated risk and that the ecosystem lags in code quality and architecture. In 2021, the ILObleed attack demonstrated how BMC vulnerabilities can be exploited to permanently destroy data on servers.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category