Blog

86,000 Servers Exposed: The BMC Vulnerability Crisis You Never Knew Existed

Published August 14th, 2026 by Bayonseo

Attackers are actively taking advantage of the little computer located deep within almost every enterprise server, which is not monitored by most IT teams. The creator of runZero, security researcher HD Moore, has discovered a "pervasive, under-monitored, under-patched parallel attack surface" in baseboard management controllers (BMCs) from the biggest server manufacturers in the world. More than 86,000 internet-connected servers expose BMC administration interfaces to the public, and more than half of them have serious vulnerabilities, according to research presented at the Black Hat security conference.


The Hidden Danger Lurking in Your Servers

Almost all enterprise servers have tiny computers called baseboard management controllers built into their motherboards. They have their own IP address, network stack, and operating system firmware, which enables administrators to keep an eye on server health and carry out operations like reinstalling operating systems and restarting machines even when the primary server is turned off. BMCs are both crucial and very risky due to their "lights-out" management capacity, also referred to as out-of-band management.

The issue is not brand-new. Since at least 2013, when vulnerabilities in the IPMI protocol allowed attackers to remotely run malicious code on the controllers and infect the servers they oversee, researchers have been alerting people to BMC vulnerabilities. According to the most recent research, not much has changed since then. Despite efforts to address them, several of the vulnerabilities Moore identified in 2013 are still present.


A Vulnerability List That Grows by the Day

More than 86,000 BMCs exposed a management service to the public, according to Moore's external scan. Over 54% of them had one or more serious flaws. Up to 75,000 of them were still susceptible to CVE-2013-4786, a flaw that makes it possible to crack administrator-level BMC account passwords offline. Nearly 29% of 126,761 BMCs had one or more significant vulnerabilities, according to an internal scan.

The weaknesses fall into several categories:

  • Vulnerabilities in authentication that allow attackers to enter the BMC
  • Inadequate integrity and encryption safeguards that permit the acceptance of unsigned commands during secure sessions
  • Attackers can take over live BMC sessions thanks to predictable session identifiers.
  • Credentials that can be recovered using offline cracking techniques, both default and factory-random
  • HPE, Supermicro, Dell, Lenovo, Huawei, Avocent, and other companies are among those impacted.


The Real-World Risk

Exploitation of BMCs is real. ILObleed, a malicious implant that affected HPE servers with wiper firmware and erased hard drive data, was found by researchers in 2021. ILObleed would persist and resume the assault even after administrators replaced hard drives and restarted the operating system. Although it had been patched four years prior, the affected devices had not yet installed the vulnerability that was exploited in that campaign.


How to Protect Your Infrastructure

Administrators can use OOBscan, an open-source application from Moore, to check all of their servers for BMC vulnerabilities. In addition to scanning, he suggests:

  • Creating complicated passwords and lengthy, distinctive usernames
  • Whenever possible, disable IPMI.
  • Turning off KCS to prevent host-side BMC access
  • Avoiding shared VLANs and isolating every BMC NIC separately


How Bayon Technologies Group Can Help

We at Bayon Technologies Group are aware that BMCs are a crucial blind spot in the majority of security initiatives. Through thorough infrastructure evaluations, ongoing monitoring, and vulnerability management initiatives, we assist clients in locating and fixing these hidden vulnerabilities. Our professionals can assist you with enforcing strict authentication procedures, implementing appropriate network segmentation, and making sure your BMC firmware is kept up to date. To close the security holes in your server, get in touch with Bayon Technologies Group right now.


‹ Back