Cybersecurity

BMC flaws expose thousands of servers to remote backdoor attacks

2 min read

BMC flaws expose thousands of servers to remote backdoor attacks
Photo: Arnold Francisca · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Thousands of Internet-connected servers from major manufacturers are vulnerable to remote backdoor attacks due to critical bugs in baseboard management controllers, according to research presented at the Black Hat security conference on August 5, 2026. The flaws, some over a decade old, allow attackers to gain deep, persistent access to data centers.

Baseboard management controllers, or BMCs, are miniature computers embedded in server motherboards that run their own firmware and network stack, enabling administrators to manage servers remotely even when they are powered off. Researchers have warned since at least 2013 that BMCs present a prime target for hackers, but the new findings show that many vulnerabilities remain unpatched.

HD Moore, CEO and founder of security firm runZero, uncovered more than a dozen new vulnerabilities in BMCs from HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. He also found that some weaknesses he flagged in 2013 are still active despite attempted fixes. Moore said the result is a pervasive, under-monitored attack surface that is both Internet-exposed and widespread inside corporate networks.

To quantify the threat, Moore conducted two large-scale scans. An external scan found over 86,000 BMCs exposing a management service to the public, with more than 54 percent containing one or more critical vulnerabilities. As many as 75,000 remained vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol that enables offline password cracking. An internal scan of 126,761 BMCs found nearly 29 percent had critical vulnerabilities.

The newly discovered bug classes include flaws in the IPMI authentication handshake that bypass authentication, failures to enforce integrity and encryption in-session, predictable session identifiers, pre-authentication memory corruptions in the SSH service, unsigned or attacker-controllable firmware, and secrets recoverable from firmware used as live credentials. Affected vendors include HPE, Supermicro, Intel, OpenBMC, Nvidia, H3C, Dell, and Huawei.

Moore has released an open-source tool called OOBscan to help administrators detect the vulnerabilities. He emphasized that BMCs remain an underrated risk, with the ecosystem lagging in code quality and architecture. Past incidents, such as the ILObleed implant in 2021 and a CISA alert on an AMI BMC flaw last year, underscore the real-world danger of these attacks.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.