
Baseboard management controllers, or BMCs, are miniature computers embedded in enterprise server motherboards that operate independently with their own operating system, network stack, and IP address. These devices enable administrators to monitor and manage server fleets remotely, including rebooting machines, installing updates, and reinstalling operating systems even when servers are offline or unresponsive. However, researchers have identified significant security gaps in BMC implementations across major manufacturers.
A firmware security expert conducting research presented at the Black Hat security conference discovered more than a dozen new vulnerabilities in BMCs from vendors including HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. An external scan identified over 86,000 Internet-connected BMCs, with more than 54 percent containing critical vulnerabilities. Approximately 75,000 devices remained vulnerable to a specific authentication protocol flaw from 2013. An internal scan of 126,761 BMCs found that nearly 29 percent had one or more critical vulnerabilities.
The vulnerabilities fall into several categories, including flaws in authentication handshakes that allow attackers to bypass security requirements, failures to enforce encryption protections during active sessions, predictable session identifiers that can be hijacked, memory corruption errors reachable before authentication, unsigned firmware allowing persistent implants, hardcoded credentials extractable from public firmware, and weak default passwords. Many of these issues can be chained together to achieve full administrative access to BMC systems.
The threat is not merely theoretical. A documented case in 2021 involved a malicious implant that infected HPE servers with firmware designed to destroy hard drive data. The implant remained active even after administrators performed standard disinfection procedures including operating system reinstallation and hardware replacement, demonstrating the persistent nature of BMC-based attacks and the challenges they pose for datacenter security.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI