Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world's biggest manufacturers are a security mess.
Recent studies have revealed that numerous Internet-connected servers sold by leading global manufacturers can be remotely compromised due to vulnerabilities in critical motherboard components. These microcontrollers, known as Baseboard Management Controllers (BMCs), are integral to enterprise servers, functioning as miniature computers embedded into their motherboards.
BMCs are responsible for monitoring server physical status and executing tasks such as rebooting machines, updating software, and reinstalling operating systems. They provide "lights out" and "out-of-band" management capabilities, meaning they operate independently of the servers they're attached to, even when those servers are powered off or unresponsive.
Since at least 2013, researchers have warned about the potential for hackers to exploit BMCs as a "pervasive, under-monitored, under-patched parallel attack surface." The primary culprit implicated in these vulnerabilities is IPMI, the protocol that enables BMCs to function independently of the servers they manage and perform administrative tasks. Vulnerabilities within this firmware allow attackers to remotely execute malicious code on the controllers, subsequently infecting the servers they oversee.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.