Patricia Renee
No Result
View All Result
  • News
    • Africa
  • Business
  • Finance
  • Investment
  • Technology
    • tech News
    • AI
    • Gadgets
  • How To
  • Food
  • Sports
  • News
    • Africa
  • Business
  • Finance
  • Investment
  • Technology
    • tech News
    • AI
    • Gadgets
  • How To
  • Food
  • Sports
No Result
View All Result
Patricia Renee
No Result
View All Result

BMC Security Flaws Expose Thousands of Servers to Hidden Backdoor Attacks

trixierenee by trixierenee
1 week ago
in AI, News, tech News
Reading Time: 10 mins read
A A
BMC security flaws

BMC security flaws could allow hackers to gain deep and lasting access to thousands of enterprise servers, according to new research presented at the Black Hat security conference in Las Vegas.

The findings reveal serious weaknesses inside baseboard management controllers, or BMCs, used by organizations to operate and monitor servers remotely. Some of the vulnerabilities are newly discovered, while others have remained unresolved for more than a decade.

Security researcher HD Moore found weaknesses affecting equipment associated with several major technology manufacturers, including HPE, Supermicro, Dell, Huawei, Lenovo, Avocent and products based on OpenBMC.

Large-scale scans also showed that many vulnerable controllers are exposed directly to the internet or remain accessible inside corporate networks.

The findings raise concerns about an overlooked security layer that can remain active even when the main server is switched off, unresponsive or undergoing repairs.

What are baseboard management controllers?

A baseboard management controller is a small computer built directly into an enterprise server’s motherboard.

Unlike the server’s main operating system, a BMC runs its own firmware, uses a separate network connection and often has its own IP address. This allows administrators to manage a server from another location.

BMCs can be used to restart machines, install updates, monitor temperature and power conditions, access remote consoles and reinstall operating systems.

These capabilities are especially valuable in large data centers, where administrators may be responsible for thousands of servers.

The technology is commonly described as “out-of-band” or “lights-out” management because it continues to operate independently of the main server. Even when a server crashes or is turned off, its management controller may remain online.

However, the same independence that makes BMCs useful can also make them dangerous when their security controls fail.

Why BMC security flaws are especially dangerous

An attacker who compromises a normal application may gain access only to that specific program or user account.

Compromising a BMC can provide much deeper control.

Because the controller sits beneath the operating system and manages essential hardware functions, an intruder may be able to monitor the server, change its configuration, install malicious firmware or regain access after the main system has been cleaned.

Traditional security tools may also struggle to detect activity taking place inside the management controller.

Moore, a firmware security specialist and founder of security company runZero, described BMC infrastructure as a widespread and poorly monitored attack surface.

His research suggests that many organizations do not regularly inspect or update the controllers installed across their server fleets.

That lack of visibility can leave weaknesses active for years.

Internet scan finds more than 86,000 exposed BMCs

To measure the scale of the problem, Moore oversaw two major scans.

The first examined BMCs that exposed management services directly to the public internet. It identified more than 86,000 devices.

More than 54% of the exposed controllers contained at least one critical vulnerability.

Researchers also estimated that as many as 75,000 devices remained vulnerable to CVE-2013-4786, a security weakness first disclosed in 2013.

The flaw affects authentication in the IPMI 2.0 protocol, which many BMCs use to communicate and perform administrative tasks.

It can allow attackers to obtain information needed to attempt offline password cracking against administrator-level accounts.

Because the password attempts occur away from the targeted server, organizations may not immediately detect the activity.

The second scan examined 126,761 BMCs operating inside corporate networks. Nearly 29% had at least one critical vulnerability.

The internal results show that removing a controller from the public internet does not eliminate the threat. An attacker who first compromises another device inside a company network may still be able to target poorly protected BMCs.

BMC security flaws affect major server manufacturers

Moore discovered more than a dozen new vulnerabilities while preparing his Black Hat presentation.

The exact number continued to increase as the research progressed. Many technical details are being withheld temporarily to give manufacturers time to prepare and distribute security updates.

However, the identified weaknesses fall into several broad categories.

Some flaws affect the IPMI authentication process. They may allow attackers to change the expected sequence of communications and bypass parts of the login procedure.

Affected products include HPE iLO, Supermicro systems and OpenBMC-based equipment from companies such as H3C and Nvidia.

Other vulnerabilities involve weak protection for data exchanged during an authenticated session. In some cases, a controller may accept an unsigned or unencrypted command even when the session was supposed to use stronger security protections.

Researchers also found predictable session identifiers in some Supermicro systems. Instead of creating session tokens using secure random data, affected products may generate them from counters or clock information.

That weakness could make it easier for an attacker to predict a valid token and take control of another user’s active management session.

Memory errors could allow code execution

Some of the most serious BMC security flaws can be exploited before an attacker successfully logs in.

Moore discovered memory corruption vulnerabilities in the management service used by certain HPE iLO systems.

A failure to properly check the length of incoming data could allow malicious code to be executed before authentication.

Pre-authentication vulnerabilities are particularly serious because attackers do not need a valid username or password to begin targeting the device.

Once limited access is obtained, attackers may combine several weaknesses to increase their privileges and take full control of the controller.

This process, known as vulnerability chaining, can turn several individually limited flaws into a much more powerful attack.

Weak firmware protections create persistent threats

The research also identified systems that do not adequately protect the integrity of their firmware or configuration settings.

On affected devices, an attacker with administrative access may be able to install modified firmware, replace verification keys or introduce a persistent implant.

Products associated with Supermicro, H3C and Dell were among those affected by firmware and configuration integrity concerns.

A malicious implant hidden inside BMC firmware could survive many standard recovery measures.

Reinstalling the server’s operating system may not remove it. Replacing storage drives may also fail because the malware is stored in a separate component on the motherboard.

Once the server returns to service, the compromised controller could potentially interfere with the operating system again.

Secrets hidden in firmware create another risk

Researchers found that some BMC firmware contains keys, constants or other secrets that can be extracted and reused.

Attackers who download publicly available firmware may be able to recover information that helps them authenticate to a controller or decrypt its network traffic.

Moore identified this type of risk in products connected to Supermicro, OpenBMC, Huawei and Dell.

Default passwords also remain a major concern.

Some organizations never replace the credentials supplied with their servers. Even when manufacturers generate a different password for each device, the available combinations may be too limited to resist determined offline attacks.

The research found that some factory-generated passwords could potentially be recovered within hours or days, depending on their length and the computing resources available to the attacker.

HPE, Supermicro and Dell products were among those identified as using credentials that could face this type of risk.

Old vulnerabilities remain active years later

The threat posed by BMC security flaws is not theoretical.

In 2021, researchers uncovered a malicious implant known as ILObleed that targeted HPE servers.

The malware used compromised BMC firmware to destroy data stored on server drives. It remained active even after administrators reinstalled operating systems or replaced hard drives.

The implant could reactivate and launch the destructive attack again because it survived inside the management controller.

The vulnerability used in the campaign had been patched four years earlier. However, the affected organizations had not installed the available update on the compromised devices.

The case demonstrated how delayed firmware patching can leave critical infrastructure exposed long after a manufacturer releases a fix.

The US Cybersecurity and Infrastructure Security Agency also added a critical vulnerability affecting an American Megatrends BMC to its list of known exploited vulnerabilities last year.

Why server operators struggle to secure BMCs

Enterprise servers often remain in service for many years.

During that time, administrators may regularly update the main operating system while paying less attention to the BMC firmware.

Some management controllers are difficult to inventory because they operate on separate networks and may not appear in standard device-management systems.

Organizations may also avoid updating BMC firmware because servers are performing important tasks and administrators fear that a failed update could cause downtime.

Older hardware can create additional problems when manufacturers reduce support or stop releasing updates.

In other cases, businesses may not realize that their management interfaces are publicly accessible.

These factors allow BMC security flaws to remain active across large numbers of systems.

New tool helps organizations find vulnerable controllers

Moore released an open-source scanning tool called OOBscan to help administrators identify vulnerable BMCs.

The tool can examine an organization’s server fleet and detect known weaknesses cataloged during the research.

Regular scanning could help security teams locate forgotten controllers, outdated firmware and exposed management services before attackers find them.

However, identifying vulnerable devices is only the first step.

Organizations must also install available patches, strengthen credentials and redesign networks to reduce unnecessary access.

How organizations can reduce BMC security risks

Administrators should use long, unique usernames as well as strong passwords for every management controller.

Using predictable administrator names can make password attacks easier, even when the passwords themselves are complex.

Organizations should disable IPMI when it is not required. Removing unused services reduces the number of possible entry points available to attackers.

Moore also recommends disabling the Keyboard Controller Style interface, commonly known as KCS, wherever possible. This can prevent the server’s main operating system from directly accessing the BMC.

Management network interfaces should also be isolated.

Instead of placing many BMCs on one shared virtual local area network, organizations should separate the interfaces as much as possible. This can limit an attacker’s ability to move from one compromised controller to others.

Most importantly, BMCs should not be exposed directly to the public internet unless there is an essential operational reason.

Remote access should pass through tightly controlled security systems with strong authentication, detailed logging and limited user permissions.

BMC security flaws reveal a hidden data center problem

The latest research shows that server security extends far beyond operating systems, applications and user accounts.

BMCs form a separate computing environment with powerful administrative access, independent network connections and their own firmware.

Yet many organizations monitor them less closely than the servers they control.

That imbalance gives attackers an opportunity to establish access at a level where ordinary security tools may not see them.

The discovery of new vulnerabilities, combined with the continued presence of flaws disclosed in 2013, suggests that the BMC ecosystem has not kept pace with modern security expectations.

For businesses, governments and data center operators, the message is clear: management controllers must be treated as critical computers rather than minor hardware features.

Without stronger monitoring, faster patching and better network isolation, BMC security flaws could continue giving attackers a hidden path into some of the world’s most important servers.

Tags: BMC security flaws
Previous Post

AI Security Risks Push White House Toward New Safety Tests

Next Post

Samsung Foldable Preorders Jump 30% as Galaxy Z Fold 8 Demand Surges

Related Posts

AI facial recognition
AI

AI Facial Recognition in Brazil: Benefits and Privacy Costs

by trixierenee
10 hours ago
0

AI facial recognition is becoming increasingly visible in Brazil, appearing in everything from security systems...

Read moreDetails
Twitch AI training
AI

Twitch AI Training Default Sparks Backlash Among Streamers

by trixierenee
12 hours ago
0

Twitch AI training has become the latest flashpoint in the debate over how technology companies...

Read moreDetails
AI inflation
AI

AI Inflation: How the Technology Boom Is Complicating the Fight Against Rising Prices

by trixierenee
2 days ago
0

Artificial intelligence is often presented as a technology that could make companies more productive, reduce...

Read moreDetails
AI autism screening
AI

AI Autism Screening Could Make Early Detection More Accessible

by trixierenee
2 days ago
0

Artificial intelligence could make autism screening easier to access by helping healthcare workers and families...

Read moreDetails
AI materials discovery
AI

AI Materials Discovery: How Experiments Are Solving Real-World Problems

by trixierenee
2 days ago
0

Artificial intelligence can predict thousands or even millions of potentially useful materials on a computer....

Read moreDetails
Pixel Watch 5
News

Google Pixel Watch 5 Goes Deeper Into AI and Proactive Health Tracking

by trixierenee
2 days ago
0

Google is taking its smartwatch ambitions deeper into artificial intelligence and health with the Pixel...

Read moreDetails
Load More
Next Post
Samsung foldable preorders

Samsung Foldable Preorders Jump 30% as Galaxy Z Fold 8 Demand Surges

affordable electric vehicles

Affordable Electric Vehicles Lead Australian Car Searches as Fuel Costs Rise

  • About Us
  • Privacy
  • Terms
  • Ad Choices
  • Contact Us
  • DMCA

© 2026 Patricia Renee News

No Result
View All Result
  • News
    • Africa
  • Business
  • Finance
  • Investment
  • Technology
    • tech News
    • AI
    • Gadgets
  • How To
  • Food
  • Sports

© 2026 Patricia Renee News