Vulnerabilities in Server Motherboard Controllers Pose Widespread Security Risk
Thousands of enterprise servers are susceptible to backdoor attacks due to newly discovered and persistent vulnerabilities in baseboard management controllers (BMCs).

Baseboard management controllers (BMCs), specialized microcomputers embedded in nearly all enterprise server motherboards, are integral for server fleet monitoring and remote administration. These controllers operate independently, featuring their own operating systems, network stacks, and IP addresses, enabling critical functions such as reboots, software updates, and OS reinstallations even when the primary server is offline or unresponsive. This "lights out" management capability has, since at least 2013, been recognized as a significant potential access point for adversaries seeking deep and persistent control over data centers. Early concerns primarily focused on vulnerabilities within the Intelligent Platform Management Interface (IPMI) protocol, which allows BMCs to execute tasks autonomously. These flaws often permitted remote code execution on the controllers, subsequently compromising the servers they managed.
Recent findings presented at the Black Hat security conference in Las Vegas indicate that many of these fundamental security weaknesses persist. HD Moore, a firmware security expert and the CEO of runZero, identified over a dozen new vulnerabilities in BMCs from major manufacturers including HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. Furthermore, Moore's investigation revealed that some vulnerabilities highlighted in his 2013 research remain unaddressed, despite earlier efforts to patch them.
Moore characterized the current landscape as a "pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize." To quantify this threat, Moore conducted two extensive scans. An external scan of Internet-facing BMCs identified more than 86,000 exposed devices, with over 54% containing at least one critical vulnerability. Approximately 75,000 of these devices were still vulnerable to CVE-2013-4786, an IPMI 2.0 authentication flaw that allows for offline cracking of administrator passwords. An internal scan of 126,761 BMCs within corporate networks showed that nearly 29% possessed one or more critical vulnerabilities.
The ongoing discovery of new vulnerabilities made it challenging to provide a precise count, and specific details are being withheld to allow vendors time to develop patches. However, Moore outlined several classes of bugs, including flaws in the IPMI authentication handshake that allow attackers to bypass authentication requirements and gain limited BMC access. Examples include products from HPE iLO, Supermicro, OpenBMC, and OpenBMC-derived offerings from H3C and Nvidia. Another significant issue involves the failure of IPMI to enforce integrity and encryption within sessions, enabling unsigned commands to be accepted in secured sessions. This vulnerability affects HPE, Supermicro, and legacy Intel products.
Other critical vulnerabilities encompass predictable session identifiers, where session tokens are generated from counters or clocks instead of secure random sources, allowing attackers to predict and hijack live BMC sessions. Pre-authentication memory corruptions, such as a length-validation error in the management SSH service that can lead to malicious code execution, were identified in HPE iLO systems. The existence of unsigned or attacker-controllable firmware and unenforced configuration integrity also presents risks, as an authenticated administrator could install persistent implants or replace firmware verification keys. This affects vendors like Supermicro, H3C, and Dell.
Moore also pointed to the use of recoverable secrets from firmware as live credentials, where keys and constants extracted from public firmware can be used for authentication or decrypting traffic. This impacts Supermicro, OpenBMC, Huawei, and Dell. Lastly, default and factory-random credentials often remain vulnerable due to hash disclosure enabled by CVE-2013-4786. While some vendors like HPE, Supermicro, and Dell use longer default passwords to increase cracking difficulty, these often remain susceptible to offline attacks. Many of these vulnerabilities can be exploited following authentication, a condition frequently met by leveraging a smaller number of pre-authentication flaws. Attackers with limited BMC access can also install old, unpatched, or backdoored firmware images to gain further control.
The exploitation of BMC vulnerabilities is not theoretical. In 2021, researchers uncovered ILObleed, a malicious implant that infected HPE servers with wiper firmware, destroying data on hard drives. This malware persisted and reactivated even after common disinfection attempts, including OS reinstallations and hard drive replacements. The vulnerability leveraged by ILObleed had been patched four years prior but remained unapplied in compromised systems. More recently, the Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in an AMI BMC to its list of known exploited vulnerabilities.
To assist administrators, Moore released OOBscan, an open-source tool designed to scan server fleets for the cataloged BMC vulnerabilities. Beyond using OOBscan, administrators can implement several defensive measures to counter most of these attacks. Moore emphasized that BMCs continue to be an underestimated security risk, suggesting that the ecosystem lags in terms of code quality and architectural robustness.
The ongoing research underscores the critical need for organizations to regularly audit their BMCs, apply timely patches, and manage these controllers with the same rigorous security protocols applied to their primary servers.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



