CVE Tools

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Ars Technica (Security)By Dan Goodin

ResearchBaseboard Management Controllers (BMCs)

Our summary

Critical vulnerabilities have been identified in baseboard management controllers (BMCs) from top server manufacturers like HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. These flaws could allow remote attackers to backdoor thousands of servers by exploiting long-standing issues in BMC firmware. Researchers found that many of these problems, including some dating back over a decade, remain unaddressed despite prior warnings. The vulnerabilities span authentication bypasses, predictable session tokens, and weak encryption enforcement, among others. Some require initial access but can be chained together to achieve full control. With over 86,000 Internet-connected BMCs exposed and more than half containing critical flaws, the situation highlights a widespread and under-protected attack surface.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store