CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3950

As cited

Copy frozen at (site build).

vulnerabilities

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Researchers have disclosed critical vulnerabilities in baseboard management controllers (BMCs) embedded in enterprise server motherboards that allow remote code execution and persistent backdoor installation. BMCs are miniature computers running separate firmware and network stacks, used for out-of-band server administration including monitoring, rebooting, and OS reinstallation, and some vulnerabilities have existed for over a decade. The IPMI protocol enabling BMC independence creates what researchers call a pervasive, under-monitored attack surface exploitable across thousands of servers from major manufacturers.

Why it matters: Datacenter operators and cloud providers managing large server fleets face critical risk: attackers gaining BMC access bypass the main server's security controls and establish persistent backdoors even when servers are powered off or fully compromised, requiring immediate vulnerability assessment and patching of motherboard firmware.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary