Ethical Hacking News
Thousands of Internet-connected servers sold by major manufacturers can be remotely backdoored using critical vulnerabilities in their motherboard controllers. Researchers have identified over a dozen new vulnerabilities, including those affecting top brands like HPE, Supermicro, and Dell. To protect against these attacks, administrators must take proactive measures such as patching identified vulnerabilities, disabling IPMI and KCS, and implementing secure password policies.
Thousands of servers can be backdoored by exploiting buggy motherboard controllers (BMCs). BMCs are vulnerable to deep and persistent access to data centers, posing a significant risk to administrators. New vulnerabilities have been identified in BMCs sold by top manufacturers, including flaws in IPMI authentication and integrity protections. Over 86,000 BMCs were found exposed to the public, with more than 54% containing one or more critical vulnerabilities. An open-source tool called OOBscan can be used to scan servers for growing BMC vulnerabilities. Admins can defend against attacks by setting unique usernames and complex passwords, disabling IPMI, and patching identified vulnerabilities.
Thousands of servers can be backdoored by exploiting buggy motherboard controllers, according to research presented Wednesday at the Black Hat security conference in Las Vegas. Baseboard management controllers (BMCs), which are miniature computers embedded into the motherboards of virtually every enterprise server, have been identified as a critical vulnerability that hackers can exploit to gain deep and persistent access to data centers.
Administators rely on BMCs to monitor the physical status of large fleets of servers and perform various tasks, including rebooting machines, installing updates, and reinstalling operating systems. However, researchers have warned since at least 2013 that BMCs present a "pervasive, under-monitored, under-patched parallel attack surface" that can be exploited by hackers.
Researchers have identified over a dozen new vulnerabilities in BMCs sold by top manufacturers such as HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. These vulnerabilities include flaws in the IPMI authentication handshake, failure of IPMI to enforce integrity and encryption protections, predictable session identifiers, pre-authentication memory corruptions, use of secrets recoverable from firmware as live credentials, default and factory-random credentials that can be compromised by hash disclosure, and more.
The number of new vulnerabilities has grown by the day, making it challenging for administrators to provide specific numbers. However, researchers have identified critical vulnerabilities such as CVE-2013-4786, which enables off-line cracking of administrator-level BMC account passwords. The external scan found over 86,000 BMCs that exposed a management service to the public, with more than 54 percent containing one or more critical vulnerabilities.
To highlight and quantify the threat, researchers have developed an open-source tool called OOBscan, which can be used by administrators to scan their entire fleet of servers to detect growing BMC vulnerabilities. By taking steps such as setting long, unique usernames and complex passwords, disabling IPMI wherever possible, disabling KCS wherever possible, isolating each BMC NIC individually, avoiding placing multiple on a shared VLAN, and patching the identified vulnerabilities, administrators can defend against most of these attacks.
The research highlights the ecosystem's lack of code quality and architecture, emphasizing that BMCs are still an underrated risk. The discovery of new vulnerabilities underscores the need for proactive measures to secure data centers and prevent potential breaches.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Pervasive-Under-Monitored-Parallel-Attack-Surface-Thousands-of-Servers-at-Risk-due-to-Vulnerable-Motherboard-Controllers-ehn.shtml
https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/
Published: Wed Aug 5 18:51:44 2026 by llama3.2 3B Q4_K_M