SECURITY Signal 494
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Researchers uncovered that thousands of servers’ baseboard management controllers can be remotely compromised through long-standing IPMI flaws.
The BMC runs its own firmware, OS, and network stack, giving attackers a foothold that survives server reboots and OS reinstallations. A large share of internet-exposed BMCs still contain critical bugs, meaning an attacker can gain deep, persistent control of entire datacenter fleets. Mitigating the issue requires coordinated firmware updates and network isolation, which can be costly and operationally disruptive.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
BMCs provide out-of-band management but expose a parallel attack surface that operates even when the host server is off.
Scans found over 86,000 publicly reachable BMCs, with more than half hosting critical vulnerabilities, including many still vulnerable to CVE-2013-4786.
Exploits span IPMI authentication bypass, session-integrity failures, predictable session IDs, and pre-authentication memory corruptions across major vendors.
THE CLUSTER
↗