Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Critical vulnerabilities have been identified in baseboard management controllers (BMCs) from top server manufacturers like HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. These flaws could allow remote attackers to backdoor thousands of servers by exploiting long-standing issues in BMC firmware. Researchers found that many of these problems, including some dating back over a decade, remain unaddressed despite prior warnings. The vulnerabilities span authentication bypasses, predictable session tokens, and weak encryption enforcement, among others. Some require initial access but can be chained together to achieve full control. With over 86,000 Internet-connected BMCs exposed and more than half containing critical flaws, the situation highlights a widespread and under-protected attack surface.