Thousands of server motherboards are vulnerable to controller flaws that could give attackers hardware-level control
Baseboard management controllers, or BMCs, are small computers built into nearly every enterprise server. They have their own firmware, operating system, network stack, and IP address. Administrators use them to reboot machines, install updates, reinstall operating systems, and monitor hardware, even when the main server is powered off or unresponsive. Read Entire Article
Server motherboards containing baseboard management controllers (BMCs) are facing a significant security threat due to a series of longstanding weaknesses, according to new research presented at Black Hat security conference in Las Vegas. The BMCs, which act as small computers within enterprise servers, provide deep-level control for administrators to manage various aspects of the machines, even when they are powered off.
However, these controllers have proven to be vulnerable to attacks, potentially granting attackers full hardware-level control over the servers.
The core issue revolves around the IPMI protocol, which enables BMCs to manage servers out of band. Researcher HD Moore, CEO and founder of runZero, has identified over a dozen vulnerabilities affecting BMCs from major manufacturers such as HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. The primary concern lies in the pervasive and largely unmonitored attack surface created by these exposed and vulnerable BMCs, both on the Internet and within corporate networks.
One of the most critical vulnerabilities identified is CVE-2013-4786, which affects the IPMI 2.0 authentication protocol and allows attackers to crack administrator passwords offline. Another group of vulnerabilities stems from flaws in the IPMI authentication handshake, enabling attackers to manipulate message order and bypass security checks. Additionally, IPMI's handling of session integrity and encryption is also compromised, allowing unsigned, unencrypted commands to be accepted on secured sessions.
The research also highlights pre-authentication memory corruption vulnerabilities, where an attacker can exploit length-validation flaws in the management SSH service to execute attacker-controlled code without proper authentication. Firmware integrity is another concern, as some BMCs have unsigned firmware or allow attackers to modify it, potentially leading to remote code execution and unauthorized installations of persistent implants or firmware verification keys.
To exacerbate the situation, many BMCs still use default or factory-generated credentials, making them easy targets for attackers to obtain password hashes and perform offline cracking attempts. Even when vendors use randomized passwords, the keyspaces remain small enough to be crackable. This, combined with the ability to bypass authentication through pre-authentication flaws or install backdoored firmware, creates a dangerous combination for server security.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.