Loading prices...
All news
A cracked chip revealing a glowing hidden eye — cover for the server BMC controller vulnerability news

Thousands of servers can be backdoored via buggy motherboard controllers

11:00 · 06.08.2026
4

Thousands of Internet-connected servers sold by the world's biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities — some more than a decade old — buried deep inside system motherboards. That's according to research presented Wednesday at Black Hat 2026, in a talk titled "Lights Out: BMCs Are Still Broken and Now We Have the Receipts," with a companion presentation at DEF CON 34.

Baseboard management controllers (BMCs) are miniature computers embedded into the motherboards of virtually every enterprise server. They run their own firmware, network stack, and IP address, and keep working even when the server they're attached to is powered off or unresponsive — what's known as "out-of-band" management. That independence is exactly what makes BMCs an attractive target: per research from Lava, of 36,872 internet-exposed BMC interfaces running the IPMI protocol, 24,650 disclose a password-derived authentication hash before login — the result of an architectural flaw in the IPMI 2.0 spec itself (CVE-2013-4786) that allows offline password cracking without a single detectable login attempt. More than half of the vulnerable controllers were Supermicro, with HPE and Dell servers also affected.

The BMC operates outside that trust boundary, giving an attacker control beneath the host while remaining largely invisible to protective tools.

Michael Katchinskiy, Head of Security Research at Lava
  • 36,872 BMCs were found exposed to the internet; 24,650 (67%) leak a password hash
  • 6,240 controllers accepted an empty username with a weak password; 2,340 used passwords found in public wordlists
  • A factory-default Supermicro password can be cracked in about an hour with a GPU rig; an HPE iLO password in about 32 seconds

The problem already has real-world consequences: researchers found a ransom note on one compromised HPE iLO 4 controller demanding 0.3 bitcoin — meaning attackers aren't just proving the attack works, they're already monetizing access to server infrastructure through persistent firmware backdoors that survive even a full operating system reinstall.

None of this should be read as personalized investment advice.

Published: 11:00 · 06.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!