Tech

What is a BMC vulnerability, and why it puts thousands of servers at risk

Ars Technica1 h ago
Server racks inside a data center
Server racks inside a data centerPhoto: panumas nikhomkhai / Pexels

Nearly every enterprise server's motherboard hosts a small auxiliary computer that operates independently of the main processor and operating system: the baseboard management controller, or BMC. This chip lets technicians remotely restart, monitor and service hardware even when the server is completely powered off.

Security researchers have found serious vulnerabilities in the firmware of several widely used BMC manufacturers' products. The flaws allow attackers to bypass authentication and gain full control of the BMC, then use that foothold to reach the rest of the server.

The core reason BMCs are dangerous is their position in the privilege hierarchy — above even the operating system. When an attacker compromises a BMC, malware can persist on the server even after the operating system is reinstalled, because the BMC operates in memory and storage entirely separate from the OS.

Researchers stress that this kind of attack is extremely difficult to detect. Standard antivirus software and security monitoring tools cannot reach the BMC layer, meaning malware can go unnoticed for months or even years.

In an attack scenario, once an attacker gains network access to the BMC, they can alter the server's hardware-level behavior, steal data or render the machine entirely unusable. Cloud providers and large data centers are especially vulnerable to this kind of flaw, since it can affect thousands of servers simultaneously.

Security experts say the root of the problem is that BMC firmware is often left running unpatched for years. Many organizations configure BMC software once during server setup and never update it again.

Affected manufacturers have released patches closing the flaw, but researchers note that the patching process is often slow, since BMC updates can require briefly powering down the server — creating operational friction for systems that need to run continuously.

Experts recommend that organizations completely isolate BMC interfaces from the public internet, allowing access only through trusted management networks. They also advise changing default passwords and regularly auditing BMC logs.

This kind of hardware-level vulnerability is drawing increasing attacker interest compared with software flaws, researchers note, because detection risk is lower and the impact can be far more persistent. Researchers expect this trend to grow in attacks targeting large-scale data centers in coming years.

The security community says the findings serve as another reminder that hardware supply-chain security must be taken as seriously as software security — since even the strongest software defenses can fall short when the hardware layer beneath them is not secure.

This article is an AI-curated summary based on Ars Technica. The illustration is a stock photo by panumas nikhomkhai from Pexels.

Read next

Data center server racks at night
Tech

Why has Texas paused new data center grid connections amid surging AI demand?

Texas has paused new large-scale data center connections to its ERCOT-run power grid after a surge of AI-driven interconnection requests threatened to outpace the grid's capacity, according to Ars Technica. The move is notable because the state's governor has spent the past two years promoting Texas as an AI infrastructure 'epicenter.' Similar strained connection queues have also emerged in Virginia and the PJM Interconnection region as AI data centers grow more power-hungry.

Ars Technica1 d ago