Thousands of servers can be backdoored by exploiting buggy motherboard controllers

by | Aug 12, 2026 | Technology

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Security researchers presented findings Wednesday at the Black Hat conference revealing widespread critical vulnerabilities in baseboard management controllers, miniature computers embedded in enterprise server motherboards that handle administrative tasks like system reboots and updates.

These controllers, known as BMCs, operate independently with their own firmware, network stack, and IP address, allowing administrators to manage servers remotely even when machines are powered off or unresponsive. Researchers have warned since 2013 that the IPMI protocol enabling BMC functionality presents significant security risks, yet vulnerabilities persist across products from major vendors including HPE, Supermicro, Dell, Lenovo, Huawei, and others.

Large-scale scans conducted by HD Moore, a firmware security expert, identified over 86,000 Internet-exposed BMCs, with more than 54 percent containing critical vulnerabilities. An internal survey of 126,761 BMCs found nearly 29 percent had critical flaws. Notably, as many as 75,000 devices remain vulnerable to a vulnerability disclosed in 2013 that enables offline cracking of administrator passwords. The identified vulnerability classes span authentication bypasses, encryption failures, predictable session identifiers, memory corruption flaws, unsigned firmware, and extractable cryptographic secrets.

Real-world attacks demonstrate the threat’s severity. In 2021, researchers discovered ILObleed, a malicious implant that persisted even after operating system reinstallation and drive replacement. Additionally, the Cybersecurity and Infrastructure Security Agency previously documented an exploited critical BMC vulnerability in the wild.

Researchers recommend organizations scan their server fleets using open-source detection tools to identify vulnerable devices and apply available patches, noting that BMCs remain significantly underrated security risks in enterprise environments.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI