New research presented at Black Hat reveals that thousands of enterprise servers remain vulnerable to exploitation due to persistent, unpatched security flaws in baseboard management controllers.
Key Points
- Security researcher HD Moore identified critical vulnerabilities in BMCs from major vendors including HPE, Supermicro, Dell, Lenovo, Huawei, and Avocent.
- Public internet scans identified over 86,000 exposed BMCs, with 54% containing at least one critical vulnerability.
- Internal network scans of 126,761 devices revealed that nearly 29% of corporate BMCs remain susceptible to exploitation.
- Flaws include predictable session IDs, weak authentication protocols, and memory corruption issues that allow for remote code execution.
- Moore released an open-source tool called OOBscan to help administrators identify and secure vulnerable hardware within their server fleets.