logo

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

ID: d1df42d5-416d-56ba-97e0-2ed04a51c392

STIX ID: report--d1df42d5-416d-56ba-97e0-2ed04a51c392

Feed Name: Ars Technica Security (category)

Threat Score
75/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

Author: Dan Goodin

...
...

This report summarizes multiple critical vulnerabilities in baseboard management controllers and out-of-band interfaces (IPMI/BMC/ILO/SSH/KVM) across major vendors (HPE, Supermicro, Intel legacy, Dell, Huawei, OpenBMC, H3C). Issues include failure to enforce session integrity/encryption allowing unsigned commands on secured sessions, predictable session identifiers enabling session takeover, pre-auth memory corruption in management SSH leading to possible RCE, unsigned or attacker-controllable firmware enabling persistent implants, extraction of secrets from firmware usable as live credentials, and weak/default factory-random credentials recoverable via offline cracking; proof-of-concept exploit chaining is demonstrated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.