Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Researchers have identified critical, long-standing vulnerabilities in Baseboard Management Controllers (BMCs) that allow hackers to gain persistent, remote access to enterprise servers. These microcontrollers operate independently of the main server, making them a high-value target for cyberattacks.
Why it matters
Because BMCs function even when servers are powered off, these vulnerabilities represent a severe security risk for data centers and critical infrastructure globally.
OUT OF BAND; OUT OF MIND Thousands of servers can be backdoored by exploiting buggy motherboard controllers Baseboard management controllers from the world’s biggest manufacturers are a security mess.
7 A data center corridor lined with rows of locked glass server racks filled with blinking electronic network equipment. Credit: Getty Images A data center corridor lined with rows of locked glass server racks filled with blinking electronic network equipment. Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in