BMC Vulnerabilities Leave Thousands of Servers Open to Backdoors
Original: Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Why This Matters
BMC compromises grant persistent, deep access to enterprise servers, making unpatched fleets a critical infrastructure risk.
Security researcher HD Moore revealed at Black Hat 2026 that over 86,000 internet-exposed baseboard management controllers (BMCs) are vulnerable, with 54%+ containing critical flaws—including a decade-old CVE-2013-4786 still active on up to 75,000 devices.
At the Black Hat security conference in Las Vegas on August 5, 2026, HD Moore, CEO and founder of runZero, presented research exposing widespread critical vulnerabilities in baseboard management controllers (BMCs) sold by major manufacturers including HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. Moore identified more than a dozen new vulnerabilities across these vendors' BMCs.
BMCs are microcontrollers embedded in virtually every enterprise server motherboard. They operate with their own OS firmware, network stack, and IP address, enabling 'lights out' out-of-band management—allowing administrators to reboot servers, install updates, and reinstall operating systems even when the host server is powered off.
Moore conducted two large-scale scans: one of internet-facing BMCs, and one inside corporate networks. The external scan found over 86,000 publicly exposed BMCs, more than 54% of which contained at least one critical vulnerability. Up to 75,000 remained vulnerable to CVE-2013-4786—a flaw in the IPMI 2.0 authentication protocol enabling offline cracking of administrator-level passwords—despite this vulnerability being disclosed in 2013.
Moore described the situation as 'a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize.'