logo

Backdoor in the Backplane. Doing IPMI security better

ID: e13f52dc-7e26-5772-8eff-481c0dc9af84

STIX ID: report--e13f52dc-7e26-5772-8eff-481c0dc9af84

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-03-31

Date Updated: 2026-03-24

Author: Kieran Larking

...
...

This report examines security risks in IPMI-based BMC implementations, emphasizing Supermicro exposures such as credential leakage, authentication bypass (e.g., cipher zero), and other critical CVEs (notably CVE-2013-4782 and CVE-2019-16649). It outlines attacker workflows to enumerate and exploit IPMI services (including hash retrieval and default credentials), and recommends mitigations like isolating management interfaces, enforcing strong passwords, disabling unnecessary features, and regularly auditing and updating firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.