Research presented at Black Hat in Las Vegas shows that baseboard management controllers (BMCs) — the small independent computers built into nearly every enterprise server motherboard for out-of-band management — remain a severely neglected attack surface. HD Moore, founder and CEO of security firm runZero, uncovered more than a dozen new vulnerabilities in BMCs from HPE, Supermicro, Avocent, Huawei, Lenovo, Dell and others, and found that weaknesses he had warned about back in 2013 are still active despite attempted fixes.
BMCs run their own firmware, network stack and IP address and let administrators reboot machines, deploy updates or reinstall operating systems even when a server is powered off. Because they operate below the host OS, compromising a BMC grants deep, persistent access that survives OS reinstalls and disk swaps.
Two large-scale scans quantify the exposure. An internet-wide scan found more than 86,000 BMCs exposing a management service publicly, of which over 54 percent had at least one critical vulnerability. As many as 75,000 devices remain vulnerable to CVE-2013-4786, an IPMI 2.0 authentication flaw that enables offline cracking of administrator passwords. An internal scan of 126,761 BMCs in corporate networks found nearly 29 percent carried one or more critical vulnerabilities.
The vulnerability classes Moore identified include: flaws in the IPMI authentication handshake that allow bypassing authentication (affecting HPE iLO, Supermicro, OpenBMC and OpenBMC-derived products from H3C and Nvidia); failure to enforce in-session integrity and encryption, so unsigned plaintext commands are accepted on secured sessions (HPE, Supermicro, legacy Intel); predictable session identifiers generated from counters or clocks, enabling session takeover across IPMI and KVM consoles (notably Supermicro); pre-authentication memory corruption in the management SSH service of HPE iLO; unsigned or attacker-controllable firmware allowing persistent implants (Supermicro, H3C, Dell); secrets recoverable from public firmware usable as live credentials (Supermicro, OpenBMC, Huawei, Dell); and default or factory-randomized credentials with small keyspaces crackable via CVE-2013-4786 hash disclosure (HPE worst with eight-character defaults; Supermicro and Dell slightly longer).
Many bugs require authentication, but Moore notes this barrier is usually cleared by chaining a smaller set of pre-authentication flaws, or by installing old or backdoored firmware images once limited access is gained. The threat is not theoretical: in 2021 the ILObleed implant infected HPE servers with disk-wiping firmware that persisted through OS reinstalls and drive swaps — the exploited bug had been patched four years earlier but never applied. Last year CISA added a critical AMI BMC vulnerability to its known exploited vulnerabilities catalog.
Moore released an open source scanner called OOBscan that administrators can run against their fleets to detect the cataloged BMC vulnerabilities. His other recommendations: set long, unique usernames and complex passwords, disable IPMI wherever possible, disable KCS to block host-side access to the BMC, and isolate each BMC network interface individually rather than sharing VLANs. Moore concludes the BMC ecosystem is well behind the curve in code quality and architecture.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.