Thousands of servers can be backdoored by exploiting buggy motherboard controllers
tech
Ars Technica is reporting on critical vulnerabilities discovered in the baseboard management controllers, or BMCs, embedded in thousands of enterprise servers sold by major manufacturers. These BMCs are tiny computers built into server motherboards that operate independently, with their own operating system, firmware, network stack, and IP address. They're designed to handle critical administrative tasks—monitoring servers, rebooting systems, installing updates, and even reinstalling operating systems remotely, even when the main server is down or unresponsive. Attackers who exploit vulnerabilities in the IPMI protocol governing these controllers can remotely execute malicious code on a BMC and use it as a foothold to infiltrate the servers they manage. Some of these flaws date back more than a decade, yet they remain largely unpatched, despite researchers warning about BMC risks since at least twenty thirteen.
Source: https://arstechnica.com/security/2026/08/thousands-of-ser...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton