HeadlinesBriefing favicon HeadlinesBriefing.com

Thousands of Servers at Risk from BMC Bugs

Ars Technica •
×

Baseboard management controllers (BMCs) are miniature computers embedded in every enterprise server motherboard, running their own firmware, network stack, and IP address to enable "lights‑out" management.

Research presented at Black Hat Las Vegas revealed that more than 86,000 Internet‑connected BMCs expose a management service publicly, with 54% containing one or more critical vulnerabilities. As many as 75,000 remain vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol that allows offline cracking of administrator passwords.

The discovered bug classes include authentication bypasses, lack of session integrity, predictable session IDs, pre‑authentication memory corruption, unsigned firmware, recoverable secrets, and weak default credentials. A notable real‑world exploit, ILObleed, infected HPE servers with a disk‑wiping implant that persisted even after OS reinstallation.

Defenders can mitigate risk by disabling IPMI and KCS where possible, using unique, complex passwords, isolating each BMC NIC, and scanning fleets with HD Moore’s free OOBscan tool.