By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Buggy Motherboard Controllers Expose Servers to Remote Backdoors

Thousands of enterprise servers manufactured by major global vendors are vulnerable to remote backdoors due to critical vulnerabilities discovered in their motherboard controllers. These flaws, some dating back over a decade, reside within the Baseboard Management Controllers (BMCs), which are essentially miniature computers embedded in server motherboards. BMCs operate with their own firmware, operating system, network stack, and IP address, enabling administrators to remotely monitor and manage large server fleets. This "lights out" and "out-of-band" management capability allows tasks such as rebooting, updating, and reinstalling operating systems, even when the main server is powered off or unresponsive.
Researchers have identified BMCs as a significant attack surface since at least 2013, warning of their potential for deep and persistent access to datacenters. The primary protocol implicated in these vulnerabilities is IPMI (Intelligent Platform Management Interface), which facilitates the independent operation of BMCs and their administrative functions. Exploits targeting IPMI firmware can allow attackers to remotely execute malicious code on the BMC controllers. From this compromised position, attackers can then proceed to infect the servers managed by these controllers, gaining a foothold deep within the datacenter infrastructure.
The research, presented on a Wednesday, highlights that these BMC vulnerabilities represent a "pervasive, under-monitored, under-patched parallel attack surface." The implications are significant, as compromised BMCs can provide attackers with persistent access that is difficult to detect and remediate through traditional server-level security measures. Because BMCs operate independently of the main server's operating system, they can remain a point of compromise even if the server itself is patched or reinstalled. This independent operation makes them a critical, yet often overlooked, component in overall datacenter security.
The vulnerabilities affect servers from "the world’s biggest manufacturers," indicating a widespread risk across the enterprise server market. The long-standing nature of some of these flaws suggests that many organizations may be unknowingly exposed. The research underscores the need for enhanced security practices and regular patching of BMC firmware, in addition to standard server operating system security. Addressing these deep-seated vulnerabilities is crucial for maintaining the integrity and security of critical IT infrastructure, as a compromised BMC can lead to a complete takeover of the managed server and potentially the entire network.
The discovery emphasizes a critical gap in cybersecurity awareness and practice, where the management hardware itself becomes the weakest link. Organizations relying on these servers are urged to investigate their BMC firmware versions and apply available patches to mitigate the risk of remote exploitation and unauthorized access. The research team's findings are expected to prompt manufacturers to accelerate the development and deployment of more secure BMC firmware and management protocols.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.