
Critical BMC Flaws Leave 86,000+ Enterprise Servers Open to Silent Remote Takeover
Key takeaways
- Over 86,000 internet-exposed BMCs found in scans; more than 54% carry at least one critical vulnerability.
- A 2013 IPMI flaw enabling password cracking still affects roughly 75,000 servers today.
- Affected vendors include HPE, Supermicro, Dell, Lenovo, Huawei, and Avocent.
Security researcher HD Moore, CEO of firmware security firm runZero, disclosed more than a dozen new vulnerabilities in baseboard management controllers at the Black Hat conference in Las Vegas on Wednesday. The flaws affect BMCs sold by some of the world's largest server manufacturers, including HPE, Supermicro, Lenovo, Dell, Huawei, and Avocent, and could allow attackers to remotely backdoor enterprise servers at scale.
Baseboard management controllers are small embedded computers soldered directly onto server motherboards, running their own operating systems, firmware, and network stacks with dedicated IP addresses. They exist to give administrators 'lights out' remote management — the ability to reboot machines, push updates, or reinstall operating systems even when the main server is powered down or unresponsive. That persistent, always-on connectivity is precisely what makes BMCs so attractive to attackers: compromising one means maintaining deep, durable access to an entire server, largely invisible to conventional security monitoring.
Moore's research involved two large-scale scans to quantify the real-world exposure. An external internet-wide scan located more than 86,000 BMCs with management interfaces publicly accessible, and more than 54 percent of those devices contained at least one critical vulnerability. Roughly 75,000 of them remained vulnerable to CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol first disclosed more than a decade ago that allows offline cracking of administrator-level account passwords. A separate internal corporate network scan covering 126,761 BMCs found that nearly 29 percent carried one or more critical vulnerabilities.
The newly discovered bug classes span several distinct attack types. Authentication handshake flaws in products including HPE iLO, Supermicro, and OpenBMC-derived firmware allow attackers to bypass login requirements by manipulating the message exchange sequence. Separate integrity and encryption failures mean that BMCs accept unsigned, unencrypted commands even on supposedly secured sessions — Moore developed a working proof-of-concept that chains these issues together into full administrative access. A third class involves predictable session identifiers generated from clocks or counters rather than secure random sources, allowing attackers to hijack live BMC sessions.
Moore held back specific vulnerability details ahead of the talk to give affected manufacturers time to produce patches, meaning the full scope of exposure remains partially undisclosed. His broader characterization of the situation is stark: a 'pervasive, under-monitored, under-patched parallel attack surface' that exists both on the public internet and deep inside corporate networks, far more exploitable than most organizations appreciate. Given that some of the same warnings Moore raised in 2013 remain unresolved today, the prospects for rapid industry-wide remediation appear uncertain.
The bigger picture
The persistence of CVE-2013-4786 across tens of thousands of internet-connected servers more than a decade after its disclosure is not just a technical embarrassment — it reflects a structural problem in how enterprise hardware security is maintained. Server manufacturers historically treated BMC firmware as an afterthought, bundling it with products and leaving patching almost entirely to customers who often lack visibility into what firmware version their controllers are running. The result is an attack surface that grows quietly alongside datacenter expansions while remaining largely invisible to the security operations teams monitoring the servers above it.
For competitors and the cloud infrastructure space more broadly, these findings create real differentiation pressure. Hyperscalers like AWS, Google, and Microsoft have increasingly moved toward custom silicon and proprietary BMC replacements — Google's Titan chip and Microsoft's Pluton efforts both reflect a desire to own the full firmware stack. Moore's research validates that direction and may accelerate enterprise customers asking pointed questions of traditional OEM vendors about BMC patch cadence, default configurations, and internet exposure. HPE, Supermicro, and Dell in particular face reputational risk if customers begin associating their hardware lines with persistent, unpatched remote access vulnerabilities.
The regulatory angle is worth watching closely. Critical infrastructure sectors — energy, healthcare, finance — rely heavily on the exact server hardware implicated here, and regulators in the US and EU have been expanding hardware security requirements under frameworks like NIST SP 800-193 and the EU Cyber Resilience Act. If a high-profile breach is eventually traced to a BMC vulnerability, the pressure on manufacturers to bake meaningful security into embedded controllers by default — not as an optional hardening guide — could shift from voluntary best practice to legal obligation. Organizations running on-premises datacenters should treat Moore's scan findings as a wake-up call to audit their own BMC exposure before someone else does it for them.
We flagged this story because BMC security rarely gets the mainstream coverage it deserves, and Moore's Black Hat presentation is one of the most concrete quantifications of the problem we've seen. Most of the conversation around server security focuses on software — operating systems, applications, cloud configs — while the firmware layer underneath sits quietly exposed. The fact that a flaw from 2013 is still live on 75,000 internet-facing devices tells us something important about how the industry approaches hardware-level patching, and we think our readers who work in IT, run homelabs, or follow infrastructure news deserve to understand what's actually sitting on their network. We'll be watching for vendor patch releases and any follow-up from the affected manufacturers named in Moore's research.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like

HP's Omen 15 Steps Into Victus Territory But Leaves Budget Gamers Behind
5d ago

Tech Giants Form AI Defense Pact After Rogue Model Breach Exposed Critical Security Gaps
Jul 28

DC's Mystery Mobile Fighter DCKO Leaves Console Fans Hungry for Injustice 3
Jul 21

Zero Parades' Critical Success Couldn't Save ZA/UM from Cutting 32 Jobs
Jul 19