Breaking
SecurityDeveloping Story

BMC Vulnerabilities Expose Servers

New research reveals widespread security flaws in baseboard management controllers across major global server manufacturers.

··3 hours ago·3 min read
a close up of a computer in a dark room
Photo by Tyler on Unsplash

A series of newly discovered vulnerabilities has highlighted a significant security blind spot within the foundation of modern data center infrastructure. Security researchers recently identified over 12 new flaws affecting baseboard management controllers (BMCs), which serve as critical management interfaces for enterprise hardware.

Understanding the BMC Attack Surface

BMCs function as specialized microcontrollers embedded directly into server motherboards. These components provide administrators with out-of-band management capabilities, allowing for remote power control, firmware updates, and console access even when the primary operating system is offline or the server itself is powered down. Since their introduction in the late 1990s, these chips have become a standard feature in high-performance hardware.

Because they operate independently of the main server OS, BMCs create a parallel management layer that often remains outside the scope of traditional security monitoring. The research presented at the Black Hat conference suggests that this isolation has inadvertently created a pervasive, under-patched environment that is increasingly attractive to potential attackers.

Scope of the Hardware Exposure

The vulnerabilities impact a wide range of hardware providers, including HPE, Supermicro, Dell, Lenovo, Huawei, and Avocent. These controllers are ubiquitous in enterprise servers, meaning the flaw exists within the core infrastructure of numerous organizations globally.

Researchers utilized scanning techniques to measure the extent of the risk, identifying a massive number of devices connected to the internet and residing within internal corporate networks. The findings suggest that a significant portion of these BMCs remain unpatched, leaving them susceptible to exploitation using the newly identified methods.

Quantifying the Current Risk

  • 86,000 BMCs were identified as being directly exposed to the public internet.
  • 54% of the internet-exposed BMCs were found to contain at least one of the identified flaws.
  • 120,000 BMCs were identified within internal corporate network scans.
  • 29% of the internal BMC devices were confirmed to carry at least one critical vulnerability.

The Mechanics of Exploitation

While many of the identified vulnerabilities require prior authentication to execute, researchers noted that this is not an absolute barrier for sophisticated threat actors. The presence of smaller, pre-authentication flaws provides a potential pathway for unauthorized access, which could then be used to pivot toward the more critical vulnerabilities discovered in this research.

The end result is a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize.

— HD Moore, security expert at runZero

Managing Ongoing Security Implications

For organizations, the core issue lies in the difficulty of maintaining visibility and applying updates to these specialized components. Because BMCs are managed separately from standard OS patching cycles, they often fall behind in security posture. The research indicates that some previously disclosed vulnerabilities in these systems remain active today, suggesting that current remediation processes are insufficient for the scale of the deployment.

Implications for Infrastructure Security

This discovery underscores a potential shift in how organizations must audit their hardware supply chains and internal management networks. If these controllers can be backdoored at scale, it suggests that the security of a server is only as strong as its management interface. For IT administrators and security teams, this could mean that traditional network perimeter defenses are no longer adequate to protect against threats that live within the hardware layer itself, potentially necessitating more rigorous isolation of management networks from the broader corporate environment.

#cybersecurity#bmc#servers#vulnerabilities#hardware

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories