Critical security flaws in baseboard management controllers (BMCs) from major server manufacturers including HPE, Dell, Lenovo, Huawei, and Supermicro can allow attackers to remotely backdoor thousands of internet-connected servers, researchers warned at the Black Hat security conference in Las Vegas. The vulnerabilities exist in BMCs—dedicated microcontrollers embedded in server motherboards that manage system monitoring, reboots, and OS installations even when servers are offline. These controllers run independently with their own firmware, network stack, and IP address, enabling "out-of-band" management, but also creating a hidden attack surface. Security expert HD Moore, CEO of runZero, identified over a dozen new vulnerabilities across multiple vendors and confirmed that some flaws first disclosed in 2013 remain unpatched despite prior fixes. The weaknesses affect implementations of IPMI, the protocol that allows BMCs to operate independently, and could let attackers execute malicious code on the controllers to gain persistent access to datacenters. Moore emphasized that BMCs are often overlooked in patching cycles, leaving them exposed for years. The affected servers are widely used in enterprise and cloud environments globally, increasing the risk of undetected breaches. No evidence of active exploitation was presented, but the potential for long-term compromise is high due to the privileged access BMCs hold.
The persistence of decade-old BMC flaws despite prior fixes suggests patching mechanisms are failing at the infrastructure level. This undermines trust in enterprise hardware security, especially where remote management is critical. If manufacturers cannot ensure firmware updates actually resolve known issues, organizations may face invisible threats inside trusted equipment.
Editorial note: AI-assisted opinion, not established fact. Full disclaimer →