Key facts
- Thousands of internet-connected servers are vulnerable to remote backdooring due to critical flaws in motherboard controllers.
- Baseboard management controllers (BMCs), used for out-of-band server management, are the target of these vulnerabilities.
- Some discovered vulnerabilities are over a decade old and remain unpatched.
- Research presented at Black Hat revealed new and existing critical vulnerabilities in BMCs from manufacturers including HPE, Supermicro, and Dell.
- Over 54% of over 86,000 internet-exposed BMCs and nearly 29% of 126,761 internally surveyed BMCs contained critical vulnerabilities.
- Exploits can lead to remote code execution, password cracking, and persistent implants, as demonstrated by past attacks like ILObleed.
Thousands of enterprise servers from major manufacturers are susceptible to remote backdooring due to critical vulnerabilities in their baseboard management controllers (BMCs), according to research presented at the Black Hat security conference. These BMCs, which provide out-of-band management capabilities, have long been identified as a significant security risk, with some flaws dating back over a decade and remaining unpatched.
HD Moore, CEO of security firm runZero, discovered over a dozen new vulnerabilities and found that some previously identified weaknesses persist. These flaws affect BMCs from vendors including HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others. The vulnerabilities span issues with IPMI authentication, session integrity, predictable session identifiers, pre-authentication memory corruption, and insecure firmware updates.
Large-scale scans revealed the extent of the problem: over 54% of more than 86,000 internet-exposed BMCs contained critical vulnerabilities, with as many as 75,000 susceptible to a known password-cracking flaw. An internal survey of over 126,000 BMCs showed nearly 29% had critical vulnerabilities. Attackers can exploit these issues to gain administrative access, bypass authentication, and install persistent malicious implants, potentially leading to data destruction as seen in the 2021 ILObleed attack.
