HD Moore finds new BMC bugs; some 2013 flaws remain active
Thousands of Internet-connected servers sold by the world's biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities, some of them more than a decade old, buried deep inside their motherboards. That is the finding of research presented Wednesday at the Black Hat security conference in Las Vegas.
The vulnerabilities live in baseboard management controllers, or BMCs: miniature computers built into the motherboard of virtually every enterprise server. Each BMC runs its own operating system firmware, network stack and IP address, separate from the server it sits on. Administrators use them for so-called "lights out" and "out-of-band" management: monitoring the physical status of large server fleets, rebooting machines, installing updates, even reinstalling operating systems, all without needing the server itself to be running. That is precisely what makes BMCs valuable to attackers too: they keep working even when the server they are attached to is powered off or unresponsive.
Researchers have warned since at least 2013 that BMCs are a prime target: a compromised controller offers attackers deep, persistent access to a datacenter. The main culprit has been IPMI, the protocol that lets BMCs operate independently of the servers they manage and carry out administrative tasks. Flaws in IPMI firmware have let attackers remotely run malicious code on the controller itself, then use that foothold to infect the server it oversees.
The new Black Hat research shows that little has changed since those early warnings. HD Moore, a firmware security expert and the CEO and founder of security firm runZero, uncovered more than a dozen new vulnerabilities in BMCs sold by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell and other manufacturers. He also found that some of the specific weaknesses he warned about back in 2013 remain active today, despite measures that were supposed to have fixed them.
Key facts
- Research presented Wednesday at the Black Hat security conference in Las Vegas found that thousands of Internet-connected servers from the world's biggest manufacturers can be remotely backdoored through flaws in their motherboard controllers.
- HD Moore, CEO and founder of security firm runZero, uncovered more than a dozen new vulnerabilities in baseboard management controllers (BMCs) sold by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell and other manufacturers.
- Some of the BMC weaknesses Moore first warned about in 2013 remain active today, more than a decade later, despite measures meant to fix them.
- BMCs are independent computers embedded in server motherboards, running their own firmware, network stack and IP address, and they keep functioning even when the server they manage is powered off or unresponsive.
- Researchers have flagged BMCs, and particularly the IPMI protocol that lets them operate independently of the server, as a route to deep, persistent datacenter access since at least 2013.
Why it matters
BMCs sit beneath the operating system and run on their own firmware, network stack and IP address, separate from the server's main system, which is why the piece frames BMC exposure as a "pervasive, under-monitored, under-patched parallel attack surface." A compromised BMC hands an attacker the same administrative reach a legitimate operator has: monitoring a server's physical status, rebooting it, installing updates, or reinstalling its operating system entirely, all without the server needing to be running. That reach is especially concerning given how long the problem has persisted: some flaws HD Moore first flagged in 2013 are still active today, more than a decade later, across hardware from most of the industry's biggest server manufacturers.
Who it affects
Anyone running enterprise servers with Internet-connected BMCs from the affected vendors is potentially exposed: HPE, Supermicro, Avocent, Huawei, Lenovo, Dell and other, unnamed manufacturers, according to the research. The article puts the scale at thousands of vulnerable, Internet-connected servers overall, sold by what it calls "the world's biggest manufacturers."
How to use it
This is vulnerability research presented at a security conference, not a product release: the article does not name specific CVE identifiers, give a patch status, or describe a vendor response, so there is no update list to act on yet. What it does establish is the shape of the risk. A BMC runs its own firmware, network stack and IP address and keeps working even when the host server is powered off, which makes it a separate, always-on computer attached to every server, one that needs its own inventory, network restrictions and patch discipline rather than being assumed to be covered by whatever protects the server's main operating system.
How solid is it
The findings come from a named, credentialed source, HD Moore, described as a firmware security expert and the CEO and founder of security firm runZero, presented publicly at the Black Hat security conference in Las Vegas rather than shared informally. Moore's claim about the 2013-era flaws carries its own track record: he is describing weaknesses he personally warned about more than a decade ago, then confirmed are still active now, rather than repeating someone else's warning secondhand. That said, the piece does not name specific CVE identifiers, give an exact count of vulnerable servers beyond "thousands," or say which additional vendors fall under "others" beyond HPE, Supermicro, Avocent, Huawei, Lenovo and Dell, so several technical details remain to be published or independently confirmed.
Risks and caveats
The write-up leaves several specifics open: no CVE identifiers for the newly discovered bugs, no exact count of vulnerable servers beyond "thousands," no vendors named beyond HPE, Supermicro, Avocent, Huawei, Lenovo and Dell despite a reference to unspecified "others," and no mention of vendor responses, patch status or disclosure timeline. The specific 2013-era flaws that Moore found still active are not identified by name either, so organizations cannot yet check their own hardware against a concrete list. Until vendors publish advisories, the underlying risk stands: BMCs are designed to keep working precisely when the server they are attached to is off or unresponsive, which is what makes them valuable for legitimate administration and attractive to attackers alike.