
Baseboard management controllers, or BMCs, are miniature computers embedded in enterprise server motherboards that provide remote administrative access even when systems are powered down. These devices run independent operating systems and network stacks, enabling administrators to monitor server health, perform reboots, install updates, and manage entire datacenter fleets. However, security researchers have identified numerous critical vulnerabilities affecting BMCs from major manufacturers including HPE, Supermicro, Dell, Lenovo, Huawei, and others.
Firmware security expert HD Moore presented findings Wednesday at the Black Hat security conference detailing more than a dozen newly discovered vulnerabilities in BMC systems. His research revealed that external scans identified over 86,000 internet-connected BMCs, with more than 54 percent containing at least one critical vulnerability. Internal network scans of 126,761 BMCs found that approximately 29 percent had critical flaws. Notably, as many as 75,000 devices remained vulnerable to a vulnerability from 2013 affecting IPMI 2.0 authentication protocols, which allows offline cracking of administrator passwords.
The identified vulnerability categories include flaws in IPMI authentication handshakes that bypass authentication requirements, failures to enforce encryption and integrity protections during active sessions, predictable session identifiers that attackers can exploit to hijack user sessions, and pre-authentication memory corruption bugs. Additional issues involve unsigned or attacker-controllable firmware, recoverable secrets extracted from public firmware, and weak default or factory-randomized credentials susceptible to offline cracking attacks.
Moore characterized the situation as a widespread, under-monitored attack surface that remains both internet-exposed and prevalent within corporate networks. Practical threats exist beyond theoretical vulnerabilities, as demonstrated by the 2021 discovery of ILObleed, a malicious implant that infected HPE servers with firmware capable of destroying stored data. The implant persisted even after standard remediation efforts including operating system reinstallation and hardware replacement, highlighting the persistent danger posed by compromised BMC systems.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI