Reported by 1 source

The short version

  • Scans indicate tens of thousands of internet-connected servers have exposed management interfaces with critical security flaws.
  • Vulnerabilities include authentication bypasses, encryption failures, and predictable session tokens across multiple major hardware manufacturers.
  • Many systems remain susceptible to a known flaw from 2013 despite previous mitigation efforts by vendors.

A significant security risk has been identified in the foundational hardware of enterprise data centers, with researchers uncovering critical vulnerabilities in baseboard management controllers. These miniature computers, embedded within server motherboards, operate independently of the main operating system to provide remote monitoring and administrative capabilities. New findings presented at a major cybersecurity conference indicate that thousands of servers from leading manufacturers can be remotely compromised through these components.

The investigation was led by HD Moore, a firmware security expert and founder of runZero. His research highlights a persistent failure in securing the out-of-band management interfaces that administrators rely on for tasks such as rebooting machines or reinstalling operating systems. The study suggests that the threat landscape for these controllers has not improved significantly since warnings were first raised more than ten years ago regarding their susceptibility to remote attacks.

News Journal

Large-scale scanning operations conducted by Moore’s team quantified the extent of the exposure. An external scan identified over 86,000 baseboard management controllers exposing management services directly to the public internet. More than half of these devices contained one or more critical vulnerabilities. Notably, approximately 75,000 of the exposed systems remained vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol that allows attackers to crack administrator passwords offline.

Internal network scans provided further insight into corporate environments. Surveying nearly 127,000 controllers within private networks revealed that almost 29 percent possessed critical vulnerabilities. This internal exposure is particularly concerning because it indicates that even systems not directly facing the internet are at risk from lateral movement by attackers who have already breached the perimeter.

The research identified several distinct classes of bugs across products from vendors including HPE, Supermicro, Dell, Lenovo, Huawei, and Intel. One major category involves flaws in the IPMI authentication handshake, where attackers can manipulate message exchanges to bypass security requirements. This initial foothold allows for further exploitation to gain full administrative access. Affected systems include those running HPE iLO, Supermicro firmware, and OpenBMC-based solutions.

Another critical issue involves the failure of devices to enforce encryption and integrity protections during active sessions. In some cases, controllers accept unsigned or unencrypted commands even when a secure session has been negotiated. This discrepancy allows attackers to chain minor issues into full system compromises. Additionally, predictable session identifiers were found in certain systems, enabling attackers to hijack live administrative sessions by guessing tokens generated from simple counters or clocks.

Pre-authentication memory corruption errors were also discovered, particularly in HPE iLO systems. These flaws exist in the management SSH service and can be triggered before a user authenticates, potentially allowing for remote code execution. Furthermore, some firmware lacks proper signature verification, meaning an authenticated administrator could install persistent implants or replace verification keys, creating long-term backdoors that are difficult to detect.

The persistence of these vulnerabilities is attributed to the complex nature of firmware updates and the often-overlooked status of management controllers in security audits. Moore described the situation as a pervasive parallel attack surface that remains under-monitored and under-patched. The findings underscore the need for organizations to treat hardware-level management interfaces with the same rigor as application-layer security.

Vendors have been notified of the specific vulnerabilities, but details remain confidential to allow time for patch development. Until fixes are widely deployed, administrators are advised to restrict network access to baseboard management controllers and monitor for unusual activity. The research serves as a stark reminder that legacy security flaws can endure for years if not actively addressed in hardware firmware.

The implications extend beyond individual server compromise to the integrity of entire data center operations. Because these controllers function even when servers are powered off, they provide a resilient pathway for attackers to maintain access. Addressing these issues requires coordinated efforts between hardware manufacturers and enterprise security teams to ensure that out-of-band management channels do not become the weakest link in network defense.

Sources behind this briefing

Go to the original reporting

  • Ars Technica↗Thousands of servers can be backdoored by exploiting buggy motherboard controllers