Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Security researcher HD Moore has revealed that thousands of Internet-connected servers from major manufacturers, including HPE, Supermicro, Huawei, Lenovo and Dell, can be remotely compromised through critical vulnerabilities in baseboard management controllers (BMCs), the small independent computers embedded in server motherboards. Presented at the Black Hat security conference in Las Vegas, the research shows that flaws first warned about in 2013 remain widespread and largely unpatched, creating what Moore describes as a "pervasive, under-monitored" attack surface that gives hackers a route to persistent, deep access into datacentres even when the servers themselves are switched off.
BMCs allow administrators to manage fleets of servers remotely, including rebooting machines and reinstalling operating systems, but their IPMI protocol has long been a weak point. Moore's scans found more than 86,000 Internet-exposed BMCs, over 54% of which carried at least one critical vulnerability, while up to 75,000 remained open to a decade-old password-cracking flaw (CVE-2013-4786). A separate internal scan of over 126,000 BMCs on corporate networks found nearly 29% affected by critical bugs, and Moore says he has also uncovered more than a dozen new vulnerabilities, details of which are being withheld until manufacturers can issue fixes.
- Critical, often decade-old bugs in server BMCs allow remote backdoor access.
- Over 54% of 86,000 exposed BMCs online carry critical vulnerabilities.
- Researcher found new flaws too, kept secret pending vendor patches.