Thousands of servers can be backdoored by exploiting buggy motherboard controllers

| Source: Ars Technica AI

Tags: BMC security, IPMI, server security, Black Hat, HPE, Supermicro, AI infrastructure, Dell

HD Moore presented at Black Hat 2026 that 86,000+ internet-exposed baseboard management controllers have critical vulnerabilities — including a 13-year-old IPMI flaw still active on 75,000 systems — giving attackers hardware-level access to servers from HPE, Supermicro, Dell, Huawei, and Lenovo.

Details

Baseboard management controllers (BMCs) are embedded microcontrollers on every enterprise server motherboard. They run independently of the main OS, maintain a separate network stack and IP address, and provide administrators remote access even when servers are powered off. This privileged position also makes them ideal for attackers seeking persistent, hardware-level access that bypasses all software-layer security.\n\nHD Moore, founder of security firm runZero, presented at Black Hat 2026 that BMC security has barely improved since his 2013 warnings. An internet scan found over 86,000 publicly accessible BMCs, with more than 54% containing critical vulnerabilities. CVE-2013-4786 — an IPMI 2.0 authentication bypass enabling offline password cracking — still affects 75,000 internet-facing systems. An internal enterprise scan of 126,761 BMCs found 29% had one or more critical vulnerabilities. Affected vendors include HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell.\n\nFor AI infrastructure operators, this is directly relevant. Large GPU clusters rely on the same BMC management infrastructure. A compromised BMC provides persistent hardware access that survives OS reinstalls and security software. Moore characterizes this as a 'pervasive, under-monitored, under-patched parallel attack surface.'