Critical BMC flaws put thousands of enterprise servers at risk
Critical vulnerabilities in baseboard management controllers may allow attackers to remotely backdoor thousands of Internet-connected enterprise servers.

Thousands of Internet-connected servers from major manufacturers may be vulnerable to remote backdoors through security flaws embedded in their motherboard management controllers, according to research presented Wednesday. Some of the vulnerabilities are reportedly more than a decade old.
The findings focus on baseboard management controllers, or BMCs: small, independent computers built into the motherboards of virtually every enterprise server. Because these controllers can remain operational even when the main server is turned off or unresponsive, a successful attack could provide unusually deep and persistent access.
What baseboard management controllers do
A BMC is more than a simple hardware component. It operates as a miniature computer with its own:
- Operating system firmware
- Network stack
- IP address
- Administrative capabilities
System administrators use BMCs to monitor the physical condition of servers and manage large fleets of machines. Their functions can include rebooting systems, installing updates and reinstalling operating systems.
These capabilities are commonly described as “lights out” or “out-of-band” management. The terms reflect the controller’s ability to function separately from the primary server environment. Administrators can still use the BMC when the attached machine has been switched off or has stopped responding normally.
That independence is useful for remote maintenance, particularly in datacenters with many servers. It also means the BMC creates a separate path into the hardware—one that does not depend on the main operating system being available.
Why a compromised BMC is a serious threat
The same privileges that make BMCs valuable to administrators can make them attractive to attackers. A controller capable of restarting a server, changing its software or reinstalling its operating system occupies a highly trusted position within the system.
According to the reported research, critical vulnerabilities in these controllers can be exploited remotely to backdoor affected servers. An attacker who executes malicious code on a BMC could then use the controller’s access to compromise the server it manages.
This is different from a conventional attack focused only on an application or the server’s primary operating system. The BMC runs its own firmware and networking software, creating a parallel environment with administrative control over the host machine. Its ability to keep working while the host is unresponsive can also make BMC-level access especially persistent.
The research concerns thousands of servers that are connected to the Internet. The available account does not identify individual affected models, manufacturers or specific vulnerability identifiers, but it describes the systems as products sold by some of the world’s largest server manufacturers.
The longstanding risks around IPMI
Warnings about BMC security are not new. Researchers have highlighted the risks since at least 2013, when attention centered on the Intelligent Platform Management Interface, commonly known as IPMI.
IPMI is the protocol that enables BMCs to work independently of the servers they control and carry out administrative tasks. Vulnerabilities in BMC firmware have made it possible for remote attackers to execute malicious code on the controllers. From that position, attackers may be able to infect the attached servers.
The age of some of the newly discussed vulnerabilities adds to the concern. The research says certain flaws have existed for more than 10 years, suggesting that security weaknesses can remain within this management layer for long periods.
Because BMCs sit below the main operating system and use their own network presence, they represent a distinct attack surface. Monitoring or securing the host operating system alone does not remove the separate exposure created by the controller.
A powerful management layer with separate exposure
The findings highlight a basic tension in enterprise server management. BMCs are designed to offer reliable control when ordinary management channels are unavailable. That design requires independence, network access and extensive privileges—the same characteristics that can increase the consequences of a security failure.
Several elements combine to make this layer sensitive:
- BMCs are widely embedded in enterprise server motherboards.
- They remain available when attached servers are off or unresponsive.
- They can perform consequential tasks, including operating system installation.
- They use separate firmware and networking components.
- Firmware vulnerabilities can expose both the controller and its managed server.
The report does not establish that every enterprise BMC is affected, nor does it say that all exposed systems have been compromised. It identifies a remote exploitation path affecting thousands of Internet-connected servers and underscores why flaws in motherboard-level controllers can have consequences beyond a typical software vulnerability.
Conclusion
BMCs provide essential remote administration for enterprise infrastructure, but their independence and broad privileges also create a powerful route into servers. Research showing that critical, long-lived vulnerabilities can be used to backdoor thousands of systems reinforces concerns that this management layer remains an important and potentially persistent security risk.
Original reporting: Ars
Originally reported by Ars.