HPE, Supermicro, Dell servers vulnerable to BMC backdoor
Security researcher HD Moore disclosed that thousands of servers from major manufacturers such as Hewlett Packard Enterprise (HPE), Supermicro and Dell Technologies contain critical firmware flaws in their Baseboard Management Controllers (BMC). The vulnerabilities, some first reported in 2013, allow attackers to gain persistent, out‑of‑band access to servers even when they are powered off, and can be exploited to install backdoors or crack administrator credentials (e.g., CVE‑2013‑4786).
Moore presented the findings at the Black Hat Security Conference and highlighted that many of the bugs remain unpatched. He released an open‑source scanner, OOBscan, to help administrators detect vulnerable BMCs. Recommended mitigations include disabling insecure protocols such as IPMI, using strong and unique credentials, isolating BMC network interfaces, and applying firmware updates where available.
Entities: Baseboard Management Controller (BMC) · Dell Technologies · HD Moore · Hewlett Packard Enterprise (HPE) · Supermicro