Ars Technica flags BMC backdoors
- Ars Technica reported on August 6 that vulnerabilities in baseboard management controllers could let attackers backdoor internet-exposed servers from major manufacturers at scale. - Eclypsium said CVE-2024-54085, a Redfish authentication-bypass flaw in AMI MegaRAC firmware, was added to CISA’s exploited-vulnerabilities catalog in June 2025. (eclypsium.com) - AMI lists fixes in SPx_12.7+ and SPx_13.5, while CISA and NSA direct operators to BMC hardening guidance. (go.ami.com)
Ars Technica reported on Thursday that flaws in baseboard management controllers, or BMCs, could let attackers remotely backdoor thousands of servers sold by major manufacturers. The report said the weaknesses sit in the motherboard-resident controller layer that administrators use for out-of-band management, a position that gives the code privileged access beneath the host operating system. Eclypsium’s prior research on AMI MegaRAC firmware and other BMC components helps explain why the issue is significant: a compromised BMC can survive outside normal host-based defenses and can be used to control, reimage, or disrupt a server. (go.ami.com) (eclypsium.com) ### Why does a bug in a BMC matter more than an ordinary server flaw? CISA and NSA said in June 2023 that BMCs are trusted components that operate separately from the operating system and firmware to allow remote management even when a system is shut down. Their guidance said weak credentials, missed firmware updates, and poor network segmentation can leave BMCs exposed and can give attackers a pre-boot foothold. Eclypsium said in a June 26, 2025 post that BMC firmware executes outside the scope of operating-system controls and has access to all resources of the server platform. (arstechnica.com) The company said that position can give attackers persistent and stealthy access that traditional endpoint tools may not detect. ### Which flaw is at the center of this latest warning? Eclypsium said on March 18, 2025 that CVE-2024-54085 is a remotely exploitable authentication-bypass vulnerability in AMI’s MegaRAC software. The CVE record says an attacker may bypass authentication remotely through the Redfish Host Interface, with potential loss of confidentiality, integrity, and availability. (cisa.gov) AMI’s advisory lists CVE-2024-54085 with a CVSS 4.0 score of 10.0 and says fixes are available in SPx_12.7+ and SPx_13.5. Giga Computing, one server vendor using the affected firmware, said in April 2025 that updated firmware would be posted on relevant product pages. (eclypsium.com) ### How many systems are exposed? Eclypsium said its Shodan search found roughly 1,000 exposed instances tied to CVE-2024-54085 and warned there were likely more affected devices and vendors. The company said it had confirmed the vulnerability on systems including HPE Cray XD670 and ASUS RS720A-E11-RS24U, and said static analysis also pointed to an ASRock Rack device. (eclypsium.com) Dark Reading reported on July 28 that separate research by Lava found about 24,000 internet-exposed server management controllers vulnerable to CVE-2013-4786, an older IPMI 2.0 flaw that can let attackers obtain password-derived hashes and crack them offline. (go.ami.com) That finding points to a broader exposure problem in internet-facing management planes, beyond a single firmware bug. ### What can attackers do after they get in? Eclypsium said in its July 2023 “Lights Out Forever” research that successful exploitation of MegaRAC BMC flaws could allow remote control of servers, malware deployment, ransomware, firmware implants, and bricking of BMC or BIOS/UEFI components. (eclypsium.com) The company also said homogeneous data-center environments could let attackers send malicious commands across a management segment, causing repeated reboots and prolonged downtime until devices are re-provisioned. Ars Technica said Thursday that the latest reporting highlights that same risk at scale because BMCs are networked, privileged, and persistent. (darkreading.com) The article described the controller layer as an attack surface that can be overlooked compared with the host operating system or hypervisor. ### Has the U.S. government said this is being exploited? CISA said on June 25, 2025 that it added CVE-2024-54085 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Eclypsium said that was the first time a BMC vulnerability had been added to the KEV catalog. (eclypsium.com) ### What are operators supposed to do next? CISA and NSA said operators should harden credentials, apply firmware updates, and use network segmentation to reduce exposure of BMC interfaces. AMI’s advisory identifies fixed firmware branches, and vendors that integrate MegaRAC are expected to publish platform-specific updates through their support channels. (arstechnica.com) CISA’s KEV catalog remains the federal reference point for exploited vulnerabilities, and AMI’s March 2025 advisory remains the product-level source for patched versions of CVE-2024-54085. (cisa.gov) Organizations running exposed Redfish or IPMI interfaces can verify affected versions against those records and their server vendor bulletins. (cisa.gov 1) (cisa.gov 2)