Thousands of servers can be backdoored by exploiting buggy motherboard controllers

by | Aug 6, 2026 | Technology

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Security researchers presented findings Wednesday documenting widespread vulnerabilities in baseboard management controllers, miniature computers embedded in enterprise server motherboards that perform critical administrative functions. These BMCs operate independently with their own firmware, network stack, and IP address, allowing administrators to monitor servers and perform tasks such as system reboots, updates, and operating system reinstallation even when primary systems are offline.

A large-scale external scan identified more than 86,000 Internet-connected BMCs with exposed management services, with 54 percent containing one or more critical vulnerabilities. An internal scan of 126,761 devices found nearly 29 percent harboring critical security flaws. Notably, as many as 75,000 devices remained vulnerable to a 2013 vulnerability in the IPMI 2.0 authentication protocol that enables offline password cracking.

Researchers identified seven major categories of vulnerabilities across products from HPE, Supermicro, Dell, Lenovo, Huawei, and others. These include flaws in IPMI authentication handshakes that bypass security requirements, failures to enforce encryption in sessions, predictable session identifiers, memory corruption bugs accessible before authentication, unsigned firmware that allows persistent implants, hardcoded secrets recoverable from firmware, and default or easily cracked credentials. Many vulnerabilities remain unpatched despite having been identified since at least 2013.

The practical consequences of compromised BMCs are severe. A 2021 incident involved the ILObleed malware implant that destroyed data on hard drives and persisted even after operating system reinstallation and hardware swaps. Last year, a critical BMC vulnerability was designated as actively exploited in the wild.

Security experts have released scanning tools to help administrators identify vulnerable devices and recommended immediate firmware updates, stronger credentials, and enhanced network monitoring to mitigate risks from this often-overlooked attack surface within corporate networks and across the Internet-accessible server infrastructure landscape.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI