Digital Event Horizon
Thousands of servers can be compromised remotely by exploiting vulnerabilities in motherboard controllers, according to a recent study. Researchers found critical weaknesses in baseboard management controllers on systems sold by major manufacturers, which can be exploited to gain deep access to data centers and infect servers.
Thousands of servers can be compromised remotely by exploiting vulnerabilities in motherboard controllers (BMCs). BMCs on systems sold by major manufacturers can be backdoored through critical vulnerabilities that have been present for over a decade. Researchers found more than a dozen new vulnerabilities in BMCs sold by leading manufacturers, including IPMI authentication weaknesses and default credentials. Nearly 86,000 Internet-connected BMCs were found to expose a management service to the public, with over 54% containing critical vulnerabilities. Administators are advised to take measures such as setting unique usernames and complex passwords, disabling IPMI, and isolating BMC NICs individually to defend against attacks.
Thousands of servers can be compromised remotely by exploiting vulnerabilities in motherboard controllers, according to a recent study presented at the Black Hat security conference. The researchers found that baseboard management controllers (BMCs) on systems sold by major manufacturers can be backdoored through critical vulnerabilities that have been present for over a decade.
The BMCs are miniature computers embedded into server motherboards and run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and perform various tasks such as rebooting machines, installing updates, and reinstalling operating systems. However, researchers have warned since at least 2013 that BMCs present a significant security risk due to their ability to be operated independently of servers and perform administrative tasks.
The chief culprit behind the vulnerability is IPMI (Intelligent Platform Management Interface), which allows BMCs to communicate with servers without authentication. Researchers found more than a dozen new vulnerabilities in BMCs sold by leading manufacturers such as HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. Some of these weaknesses are related to the IPMI authentication handshake, failure to enforce integrity and encryption protections, predictable session identifiers, pre-authentication memory corruptions, use of secrets recoverable from firmware, and default credentials.
The researchers conducted two large-scale scans to highlight the threat: one scanned Internet-connected BMCs at large, while the other internally surveyed devices inside corporate networks. The external scan found over 86,000 BMCs that exposed a management service to the public, with more than 54% containing critical vulnerabilities. Internally, nearly 29% of BMCs had one or more critical vulnerabilities.
To quantify the threat, researchers created an open-source tool called OOBscan, which can be used by administrators to scan their entire fleet of servers and detect growing lists of BMC vulnerabilities. To defend against these attacks, administrators are advised to set long, unique usernames and complex passwords, disable IPMI whenever possible, disable KCS wherever possible, isolate each BMC NIC individually, avoid placing multiple on a shared VLAN.
The study emphasizes that BMCs are still an underestimated risk in the industry due to the ecosystem being behind the curve in terms of code quality and architecture. The researchers' findings highlight the importance of patching vulnerabilities and adopting best practices for managing BMCs to prevent such attacks.
Related Information:
https://www.digitaleventhorizon.com/articles/Thousands-of-Servers-Can-be-Backdoored-by-Exploiting-Buggy-Motherboard-Controllers-deh.shtml
https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/
Published: Mon Aug 10 19:59:36 2026 by llama3.2 3B Q4_K_M