Thousands of servers can be backdoored by exploiting buggy motherboard controllers

by | Sep 2, 2026 | Technology

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Security researchers have identified multiple critical vulnerabilities affecting baseboard management controllers (BMCs) embedded in enterprise servers from major manufacturers including HPE, Supermicro, Dell, Lenovo, and others. BMCs are miniature computers that run independently on server motherboards, providing out-of-band management capabilities that allow administrators to monitor systems, perform reboots, install updates, and reinstall operating systems even when servers are powered off or unresponsive.

The research was presented Wednesday at the Black Hat security conference and builds on warnings that have circulated since at least 2013. HD Moore, a firmware security expert and CEO of runZero, identified more than a dozen new vulnerabilities and confirmed that certain weaknesses reported over a decade ago remain unpatched. Moore conducted two large-scale scans to quantify the threat: an external scan found over 86,000 Internet-connected BMCs with exposed management services, with more than 54 percent containing critical vulnerabilities. An internal scan of 126,761 BMCs within corporate networks revealed nearly 29 percent had one or more critical vulnerabilities. As many as 75,000 devices remained vulnerable to CVE-2013-4786, a vulnerability in the IPMI 2.0 authentication protocol that enables offline cracking of administrator passwords.

The identified vulnerability classes include flaws in IPMI authentication handshakes that bypass security requirements, failures to enforce encryption and integrity protections during active sessions, predictable session identifiers that allow attackers to hijack existing sessions, pre-authentication memory corruption in SSH services, unsigned or controllable firmware that permits persistent implants, recoverable secrets in public firmware usable as live credentials, and weak default or factory-random credentials vulnerable to offline attacks.

Many vulnerabilities require some level of authentication to exploit, but Moore identified pre-authentication vulnerabilities that can serve as initial entry points. Once limited access is obtained, attackers can install backdoored firmware that persists across standard remediation efforts. A 2021 incident involving ILObleed demonstrated the real-world threat, as the malicious implant remained active even after operating system reinstalls, hard drive replacements, and other standard disinfection procedures.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI