READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Researcher Finds 86,000 Servers Exposed by Old, Unpatched Motherboard Chip Bugs

Researcher Finds 86,000 Servers Exposed by Old, Unpatched Motherboard Chip Bugs
Firmware researcher HD Moore told the Black Hat security conference that thousands of servers from HPE, Dell, Lenovo, Supermicro, Huawei, and Avocent can be remotely backdoored through vulnerable baseboard management controllers, some flaws dating back over a decade. More than half of the 86,000 internet-exposed devices he scanned had at least one critical vulnerability, proof that a known problem from 2013 never got fixed.

A security researcher told the Black Hat conference in Las Vegas this week that tens of thousands of servers worldwide can be remotely hijacked through a piece of hardware most IT administrators barely think about: the baseboard management controller.

HD Moore, founder and CEO of security firm runZero, presented findings Wednesday showing that BMCs sold by HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell contain critical vulnerabilities, according to Ars Technica. Some of the flaws are brand new. Others have been sitting unpatched since at least 2013.

A BMC is essentially a tiny computer bolted onto a server's motherboard. It runs its own operating system, its own firmware, and its own network stack, with its own IP address, completely separate from whatever operating system the server itself is running. That's by design. Administrators use BMCs to reboot machines, push updates, and manage hardware remotely, even when the main server is powered off or frozen. It's called "out-of-band" management for a reason: it works when nothing else does.

That same design makes BMCs a dream target for hackers. If you compromise the BMC, you get a foothold that survives reboots, operating system reinstalls, and most detection tools, because the malware is living below the level anything else on the machine can see.

The Numbers Are Bad

Moore ran two scans to size up the problem. One looked at BMCs exposed directly to the public internet. The other scanned devices sitting inside corporate networks.

The external scan turned up more than 86,000 internet-connected BMCs with a management service publicly exposed. Of those, over 54 percent, more than 46,000 devices, had at least one critical vulnerability, according to Ars Technica's reporting on Moore's presentation.

Roughly 75,000 of the exposed devices were still vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol that lets an attacker crack administrator passwords offline. That vulnerability is old enough to buy a beer. It's been public and documented for over a decade, and three-quarters of the exposed BMCs Moore scanned are still wide open to it.

The internal network scan, covering 126,761 BMCs sitting inside corporate environments rather than facing the open internet, found nearly 29 percent had one or more critical vulnerabilities.

Moore also said the tally of newly discovered vulnerabilities kept climbing in the weeks leading up to his talk, to the point where he couldn't give a firm final count. He's keeping the technical details of the new bugs under wraps until vendors patch them, standard practice for responsible disclosure, but it means the full scope of the problem isn't public yet.

Why This Keeps Happening

IPMI, the protocol that lets BMCs operate independently of the servers they're attached to, has been flagged as a security liability since researchers first raised alarms in 2013. Ars Technica's reporting on Moore's talk makes clear that little has changed structurally in the years since: the same class of authentication weaknesses that got attention over a decade ago are still shipping on hardware from the largest server manufacturers on the planet.

Part of the problem is visibility. BMCs run their own firmware stack that most vulnerability scanning and patch management tools never touch, because they're not looking at the server's actual operating system. Moore's quote to Ars Technica captures the issue directly: he calls it "a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize."

This observation comes from someone who spent months scanning real infrastructure and finding the exact flaw the industry has known about since 2013 still sitting open on tens of thousands of machines.

What Happens Now

Moore is withholding specifics on the newly discovered vulnerabilities until affected vendors, which reportedly include HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell, can issue patches. No timeline for those patches has been made public yet.

For IT administrators, the immediate takeaway from the research is straightforward: BMCs should never be exposed directly to the public internet, and any BMC firmware still running IPMI 2.0 authentication without additional hardening is a known, decade-old liability, not a theoretical one.

The unresolved question is how many of the roughly 86,000 exposed devices Moore identified belong to organizations that have no idea their server management hardware is sitting open to attackers. Given that this exact class of vulnerability was first flagged publicly in 2013, the more uncomfortable question is why the patching rate has been so slow for so long.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaThousands of servers can be backdoored by exploiting buggy motherboard controllers