Crosswords Sudoku and Comics
Science

Thousands of Enterprise Servers Vulnerable to Backdoor Attacks Through Motherboard Controllers

A security researcher found more than a dozen new vulnerabilities in baseboard management controllers sold by major manufacturers including HPE, Dell, and Lenovo.

ASPEED AST2400 BMC on a server motherboard
ASPEED AST2400 BMC on a server motherboard      Server Motherboard Bmc    Phiarc / Wikimedia Commons (CC BY-SA 4.0)
By Free News Press Editorial Team
Published August 6, 2026 at 1:14 AM PDT

A security researcher presented findings at a major conference this week showing that thousands of internet-connected servers from the world's largest manufacturers remain vulnerable to remote attacks through a little-monitored component buried deep inside their hardware.

The research was presented Wednesday at the Black Hat security conference in Las Vegas by HD Moore, a firmware security expert and the CEO and founder of security firm runZero. Moore identified more than a dozen new vulnerabilities in components called baseboard management controllers, or BMCs, found in servers made by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others.

BMCs are small computers embedded directly into server motherboards. They run their own operating system, their own network connection, and their own IP address, separate from the main server. System administrators use them to monitor large fleets of servers remotely and to perform tasks like rebooting machines, installing software updates, and reinstalling operating systems. Because BMCs function even when the servers they are attached to are turned off or unresponsive, they are described as providing "lights out" and "out-of-band" management.

That independence is also what makes them dangerous. According to a report by Ars Technica, researchers have warned since at least 2013 that BMCs represent what Moore's research describes as a "pervasive, under-monitored, under-patched parallel attack surface." An attacker who gains access to a BMC can remotely execute malicious code on the controller and from there reach the servers it manages, potentially affecting entire data centers.

The protocol at the center of the problem is called IPMI, which allows BMCs to operate independently and carry out administrative functions. Vulnerabilities in IPMI firmware have been known for over a decade, but Moore's new research shows that some of the same weaknesses he flagged in 2013 remain active today, despite patches that were supposed to address them.

The implications are significant for any organization running large server infrastructure. BMCs are present in virtually every enterprise server, meaning the vulnerable attack surface spans industries from finance to health care to government. Because the controllers sit below the operating system layer, malware installed through a BMC compromise can be extremely difficult to detect and remove.

Moore's presentation did not detail whether any of the newly discovered vulnerabilities have been actively exploited in the wild. The findings add urgency to calls from the security community for organizations to audit and update BMC firmware, which is often left unpatched for years.

Server Motherboard Bmc    Pixabay (free for editorial use)