
Firmware security experts have identified significant vulnerabilities affecting baseboard management controllers embedded in enterprise servers from leading manufacturers including HPE, Supermicro, Dell, Lenovo, and others. These miniature computers operate independently within server motherboards and provide critical administrative functions such as system monitoring, remote rebooting, and firmware updates even when servers are offline. Researchers warned of security risks associated with these devices and the IPMI protocol they use at least since 2013, yet patching efforts have proven inadequate.
Large-scale scans of Internet-exposed and corporate network-based controllers revealed the scope of the problem. An external survey identified more than 86,000 publicly accessible baseboard management controllers, with more than 54 percent containing critical vulnerabilities. An internal assessment of over 126,000 devices found that nearly 29 percent had at least one critical flaw. Notably, as many as 75,000 Internet-facing controllers remained vulnerable to a vulnerability first disclosed in 2013 that enables offline cracking of administrator credentials.
Vulnerabilities fall into several categories affecting multiple manufacturers. These include flaws in authentication handshakes that allow bypassing security checks, failures to enforce encryption and integrity protections during active sessions, predictable session identifiers that permit hijacking of legitimate user connections, and memory corruption bugs accessible before authentication. Additional weaknesses involve unsigned firmware that can be replaced with backdoored versions, extraction of authentication secrets from publicly available firmware, and default credentials with insufficient entropy for secure randomization.
The threat extends beyond theoretical risk. A 2021 malware campaign demonstrated practical exploitation through a persistent implant that infected HPE servers, destroying data on hard drives through firmware-level attacks that survived standard remediation procedures including operating system reinstallation and hardware replacement. Security experts characterize the landscape as a “pervasive, under-monitored, under-patched parallel attack surface” that presents significant risk to enterprise datacenters worldwide.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI