86,000 Internet-exposed BMCs show 54% critical vulnerability rate in runZero Black Hat scan
runZero scans quantified BMC exposure at scale. Over half of externally reachable devices carry critical IPMI flaws, some dating to 2013. This parallel attack surface persists due to firmware patching inertia and independent network stacks.
HD Moore's Black Hat presentation documented IPMI handshake bypasses affecting HPE iLO, Supermicro, OpenBMC, H3C, and Nvidia-derived controllers, plus in-session integrity failures in Dell and Lenovo firmware. Internal scan of 126,761 devices found 29% with critical flaws. These controllers operate independent of host OS, retaining administrative access even when servers are powered down.
CVE-2013-4786 offline password cracking remains active on up to 75,000 devices despite 2013 disclosure. New classes include altered authentication sequences granting initial toeholds followed by privilege escalation. Primary source is Moore's runZero firmware telemetry; secondary data from 2013-2024 IPMI CVE lists show repeated failure of vendor patches to reach production fleets.
Operationally, exposed BMCs create persistent out-of-band entry points that bypass host monitoring and EDR. Data centers cannot rely on server OS patches for remediation. Firmware updates require physical or authenticated BMC access, creating a circular dependency that delays deployment.
Vendors have received details under embargo. Public disclosure timeline and patch availability remain undetermined as of the presentation.
runZero: Fewer than 15% of the 86,000 exposed BMCs will receive firmware patches within 180 days of disclosure.
Sources (2)
- [1]Primary Source(https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/)
- [2]Supporting Source(https://www.blackhat.com/us-26/briefings/schedule/#firmware-security-bmc-issues-2026)