Critical Motherboard Flaws Expose Thousands of Servers to Remote Backdoor Attacks
Thousands of internet-connected servers sold by major manufacturers like HPE, Dell, Lenovo, and Supermicro remain vulnerable to remote backdoor attacks through critical flaws in their baseboard management controllers. Security researcher HD Moore presents these findings at the Black Hat security conference in Las Vegas, revealing more than a dozen new vulnerabilities in BMCs from several leading hardware vendors. Some of the weaknesses date back over a decade and still remain unpatched.
Baseboard management controllers function as miniature computers embedded directly into server motherboards, complete with their own operating systems, network stacks, and IP addresses. Administrators depend on them for out-of-band management tasks such as monitoring server health, rebooting machines, and reinstalling operating systems. Because BMCs operate independently even when servers are powered down, they create what researchers describe as a pervasive and under-monitored parallel attack surface that hackers eagerly exploit.
Moore, now the CEO of security firm runZero, first warned about BMC vulnerabilities in 2013, but his latest research demonstrates that little progress has been made since then. The flawed IPMI protocol that enables BMC functionality continues to allow attackers to remotely execute malicious code on the controllers and subsequently infect the servers they manage. The findings underscore a persistent industry failure to address deeply embedded firmware security issues across the global data center supply chain.