Thousands of servers can be backdoored by exploiting buggy motherboard controllers

by | Aug 29, 2026 | Technology

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Security vulnerabilities in baseboard management controllers embedded in enterprise servers pose a significant threat to datacenter infrastructure, according to research presented at the Black Hat security conference. These microcomputers, known as BMCs, operate independently of servers with their own operating system, network stack, and IP address, allowing administrators to monitor and manage large server fleets remotely even when systems are offline or unresponsive.

Firmware security expert HD Moore identified more than a dozen new vulnerabilities in BMCs manufactured by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. Additionally, Moore found that some weaknesses he originally documented in 2013 remain unpatched despite prior remediation efforts. Large-scale scanning revealed the extent of the exposure: an external scan identified over 86,000 Internet-connected BMCs, with more than half containing critical vulnerabilities. An internal survey of approximately 126,761 devices found that nearly 29 percent harbored one or more critical flaws.

The identified vulnerability categories include authentication bypass flaws in IPMI protocols, failures to enforce encryption during sessions, predictable session identifiers that allow hijacking of user sessions, memory corruption exploitable before authentication, unsigned firmware that enables persistent backdoors, secrets embedded in firmware that serve as live credentials, and weak default passwords susceptible to offline cracking attacks. Many older vulnerabilities, including CVE-2013-4786 from 2013, remain active in as many as 75,000 exposed devices.

While some vulnerabilities require prior authentication access, researchers demonstrated how limited pre-authentication exploits can serve as entry points for installing backdoored firmware or achieving administrative control. The practical threat extends beyond theoretical risk; a 2021 incident involving the ILObleed malware infected HPE servers and persisted even after standard remediation procedures, including operating system reinstallation and hardware replacement.

Moore characterized the situation as a widespread, inadequately monitored attack surface that remains highly exploitable despite years of awareness regarding BMC security risks. The vulnerabilities affect both Internet-exposed and internal corporate network devices across major server manufacturers.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI