
Researchers presented findings at Black Hat showing that baseboard management controllers embedded in enterprise servers from leading manufacturers contain numerous critical security flaws that could allow remote backdoor access. BMCs are specialized microcomputers that operate independently on server motherboards, enabling administrators to manage physical hardware, perform reboots, install updates, and reinstall operating systems even when servers are offline or unresponsive.
HD Moore, a firmware security expert, conducted large-scale scans of both Internet-connected and internal corporate BMCs to assess the threat landscape. An external scan identified more than 86,000 publicly exposed BMCs, with over 54 percent containing critical vulnerabilities. An internal survey of 126,761 BMCs found approximately 29 percent had one or more critical vulnerabilities. Notably, as many as 75,000 devices remained vulnerable to a 2013 authentication vulnerability in the IPMI protocol, indicating that security issues from over a decade ago persist despite patch availability.
Moore identified seven categories of vulnerability classes affecting BMCs from HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and other major vendors. These include authentication bypass flaws, lack of encryption enforcement during active sessions, predictable session identifiers, pre-authentication memory corruption, unsigned firmware, and hardcoded credentials recoverable from public firmware. While many vulnerabilities require prior authentication, attackers can chain multiple flaws together or exploit pre-authentication vulnerabilities to gain initial access.
The practical risks are demonstrated by prior incidents, including the 2021 ILObleed malware that persisted on HPE systems even after operating system reinstallation. Moore released an open source scanning tool called OOBscan to help administrators identify vulnerable BMCs in their infrastructure and recommended prioritizing firmware updates and credential management to mitigate attack surface exposure.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI