Critical vulnerabilities in baseboard management controllers expose thousands of servers to remote backdoors
Researchers found over a dozen new vulnerabilities in BMCs from major vendors, with more than 54% of internet-exposed devices affected by critical flaws, some dating back to 2013.
1 source · cross-referenced
- More than 86,000 internet-connected BMCs expose management services, with over 54% containing critical vulnerabilities.
- Nearly 29% of 126,761 BMCs surveyed internally had one or more critical vulnerabilities.
- Vulnerabilities span authentication bypasses, memory corruption, and weak default credentials across HPE, Supermicro, Dell, and others.
- Exploits could enable persistent access, data destruction, or lateral movement within corporate networks.
Research presented at the Black Hat security conference detailed more than a dozen new vulnerabilities in baseboard management controllers (BMCs) sold by major manufacturers, including HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. BMCs are miniature computers embedded in server motherboards that run independent firmware and network services, enabling administrators to monitor server health and perform tasks such as rebooting, updating, or reinstalling operating systems—even when servers are powered off or unresponsive.
The vulnerabilities, some dating back to 2013, include flaws in the Intelligent Platform Management Interface (IPMI) protocol and other components, allowing attackers to bypass authentication, execute arbitrary code, or take over active sessions. HD Moore, the firmware security expert and CEO of runZero who uncovered the issues, described BMCs as a "pervasive, under-monitored, under-patched parallel attack surface" that is often exposed to the internet and widely present within corporate networks.
An external scan identified over 86,000 internet-facing BMCs, with more than 54% containing one or more critical vulnerabilities. Among these, as many as 75,000 devices remained vulnerable to CVE-2013-4786, a long-standing flaw in the IPMI 2.0 authentication protocol that enables offline cracking of administrator passwords. An internal scan of 126,761 BMCs found nearly 29% had critical vulnerabilities, underscoring the scale of exposure beyond just internet-facing devices.
The vulnerabilities span multiple classes, including authentication bypasses during the IPMI handshake, failures to enforce encryption or integrity protections, predictable session tokens, pre-authentication memory corruption, and the presence of unsigned or attacker-controllable firmware. Affected vendors include HPE (notably its iLO systems), Supermicro, Dell, Huawei, Intel, and others. Some issues, such as default or factory-randomized credentials, remain exploitable due to weak key spaces, allowing offline recovery of administrative access.
Moore emphasized that while some vulnerabilities require initial access, many can be exploited pre-authentication or chained together to achieve full administrative control. Attackers could then install persistent implants, replace firmware verification keys, or leverage BMCs as footholds to move laterally within corporate networks. Historical precedent for such attacks exists: in 2021, researchers discovered ILObleed, a malicious implant targeting HPE servers that destroyed data on hard drives and persisted even after reinstallation of operating systems or hardware replacement.
- Aug 6, 2026 · Simon Willison’s Weblog
Meta’s Muse Spark model exploited a security vulnerability during third-party testing
Trust75 - Aug 6, 2026 · Simon Willison’s Weblog
OpenAI details third-party cybersecurity evaluation incidents involving its models
Trust79 - Aug 5, 2026 · The Verge — AI
AI agents from OpenAI and Anthropic displayed deceptive behavior in UK safety tests
Trust74