Your enterprise servers contain critical server backdoor vulnerabilities that could allow attackers full control, even bypassing your operating system defenses. These vulnerabilities lie within Baseboard Management Controllers (BMCs) like HPE iLO, Supermicro IPMI, and Dell iDRAC. They act as independent “sanctioned backdoors” to your hardware.
At CTS, we’ve seen firsthand how easily these can be exploited if not properly secured, exposing everything from sensitive data to million-dollar GPU arrays. The problem isn’t new, but it’s getting worse.
Security researcher HD Moore, co-founder of runZero, disclosed 123 confirmed vulnerabilities across eight vendors at DEF CON 34. This isn’t just about remote power cycling anymore; these bugs allow for code execution on the host server itself, often with no credentials required. Imagine an attacker booting your server, installing their own OS, and your robust cybersecurity stack being completely irrelevant.
It’s a nightmare scenario, and it’s happening because of fundamental flaws in protocols like IPMI 2.0 and even the open-source OpenBMC project. Many of these exposures start with something as simple as a shared network port.
Servers often ship with one physical NIC for both the host and the BMC. If a configuration resets, the BMC can grab an IP via DHCP on whatever subnet it’s plugged into. We’ve walked into countless client sites where an accidental DHCP assignment put a BMC directly on a production network, or worse, internet-facing.
According to runZero’s internet-wide scans, roughly 51,000 devices respond to IPMI, with 23,000-25,000 of those handing over crackable password hashes without authentication. On internal networks, the trivially exploitable share has jumped from 12% to about one in three after these new disclosures. That’s a staggering level of risk.
Here’s what nobody is talking about: the vendor-specific “fixes” often create new vulnerabilities. Supermicro, for instance, added a hardcoded password to prevent hash leaks, but that fix became a bypass itself. It’s like patching a hole in your roof with a bigger hole.
And with shared codebases like OpenBMC, a single bug in an authentication flow can affect Supermicro, Nvidia BlueField, Intel, and Google hardware all at once. An attacker can set an invalid privilege level during an RAKP handshake and fall back to a default key built into the OpenBMC code, bypassing your actual password. This isn’t theoretical; runZero even released an open-source tool, OOBscan, to automate these bypass techniques. They essentially said, “We won. Most IPMI devices are now trivially exploitable.”
What are the immediate steps to close these server backdoor vulnerabilities?
You need to act now. Here’s what we at CTS recommend, based on decades of deploying and securing enterprise infrastructure:
- Isolate management traffic: Implement dedicated VLANs for all BMC traffic. This is non-negotiable. Even if an attacker exploits a pre-authentication flaw, segmenting ensures they can’t pivot directly into your production network. We’ve seen this with clients who, after a network audit, realized their iDRACs were sitting right next to their SQL servers on the same subnet.
- Use dedicated management NICs: Stop sharing physical ports. A dedicated management NIC physically separates the BMC from the host OS network, reducing the chance of accidental exposure and making it easier to apply strict firewall rules.
- Disable KCS if not needed: Keyboard Controller Style (KCS) is an in-band channel that lets the host OS talk to its BMC. If you don’t need it, disable it. Leaving it on gives anyone with host root access a direct path to the BMC, nullifying your out-of-band security efforts.
- Set unique, strong credentials: This sounds basic, but it’s still the biggest weakness. Change default passwords immediately. Use complex, unique credentials for every single BMC. Don’t reuse passwords. Ever.
- Prioritize Redfish over IPMI: Where your hardware supports it, transition from IPMI to Redfish. Redfish is a newer, more secure management standard defined by the DMTF (Distributed Management Task Force). Crucially, ensure IPMI is disabled at the network level, not just in the BMC interface. If your hardware is still running IPMI, make sure it’s the only management protocol available.
Ignoring these server backdoor vulnerabilities is like leaving the keys to your data center under the doormat. If you need help auditing your network for these exposures, or implementing a more robust cybersecurity framework, reach out. We’re here to help.
Frequently asked questions
What is a Baseboard Management Controller (BMC)?
A BMC is hardware embedded in server motherboards that provides remote power control, console access, and firmware updates independent of the host operating system, often using the IPMI protocol.
How do BMCs become exposed to attackers?
BMCs often become exposed when they share a physical network port with the host server and accidentally pick up an IP address via DHCP on a production or even internet-facing subnet due to misconfiguration or resets.
What is the risk if a BMC is exploited?
If a BMC is exploited, attackers can gain full control over the host server, often achieving code execution and bypassing the server's own operating system defenses, making server security irrelevant.
What is Redfish and why is it preferred over IPMI?
Redfish is a newer, more secure standard for server management compared to the older IPMI protocol. It offers improved security features and a more modern API, reducing the attack surface for management interfaces.
Related reading
- AI Network Traffic: 4 Hidden Costs & Your Fix
- Stop 5 Wi-Fi Mistakes: Your APs Are Failing You
- Stop Wasting Money on Warehouse Wi-Fi
Ready to upgrade your technology?
Complete Tech Solutions designs, installs, and supports IT, cabling, security, and network infrastructure for businesses across Grand Rapids, West Michigan, and nationwide. Schedule a free site assessment and we’ll map out the right solution for your space and budget.
Learn more about our Consulting services.