Particle.news

Widespread Critical Flaws Found in Server Baseboard Management Controllers

Black Hat disclosures and scans show tens of thousands of internet‑exposed management controllers have critical vulnerabilities that demand immediate mitigation.

Overview

  • HD Moore of runZero disclosed more than a dozen new BMC vulnerabilities at Black Hat this week and published OOBscan, an open source tool to help administrators locate affected controllers.
  • Large scans found roughly 86,000 BMCs exposed to the public Internet with about 54 percent carrying at least one critical flaw and an internal survey of 126,761 BMCs showing nearly 29 percent with critical issues.
  • The flaws include broken IPMI authentication, predictable session tokens, pre‑authentication memory corruption, weak firmware integrity, and recoverable secrets, which can be chained to gain full, persistent control of servers.
  • Researchers warn that some problems trace to a decade‑old IPMI weakness (CVE‑2013‑4786) that allows offline cracking of administrator credentials and that compromised BMCs can host implants that survive OS reinstallations.
  • RunZero and security teams advise immediate steps—scan with OOBscan, isolate BMC network interfaces, disable IPMI and KCS where possible, and enforce long unique credentials—while vendors work on coordinated patches and authorities monitor exploited BMC flaws.