Skip to content

runZero Research: BMC Vulnerabilities

runZero Discovers Critical BMC Vulnerabilities

Overview: The runZero research team has uncovered a series of security flaws affecting prominent Baseboard Management Controller (BMC) systems. These vulnerabilities allow malicious actors to hijack or disrupt management subsystems, potentially circumventing network segmentation entirely. Comprehensive technical breakdowns and specific CVEs will be released upon the completion of coordinated disclosure procedures.

Understanding the Threat Landscape

Baseboard Management Controllers are specialized microcontrollers deeply embedded within enterprise servers. Because they operate on dedicated firmware and utilize separate network interfaces, they function completely independently of the host’s primary operating system. In fact, a BMC remains active and accessible over the network even when the main server is powered down.

A vast majority of these devices depend on the Intelligent Platform Management Interface (IPMI) protocol. Back in 2013, researcher Dan Farmer exposed catastrophic architectural weaknesses in IPMI, including Cipher Zero authentication bypasses and the leaking of RAKP password hashes. While the cybersecurity community has identified various vendor-specific bugs since then, the foundational implementations of the core IPMI protocol have rarely been subjected to modern, rigorous re-examination.

Upcoming Presentations

We will be sharing an in-depth analysis of these findings at two upcoming conferences:

  • Black Hat 2026: “Lights Out: BMCs Are Still Broken and Now We Have the Receipts”
  • DEF CON 34: “Lights Out: Out-of-Band, Out of Mind, Out of Control”

Affected Implementations

The vulnerabilities impact a wide array of major BMC environments, including:

  • OpenBMC
  • Supermicro IPMI
  • HPE iLO
  • Dell iDRAC
  • AMI MegaRAC
  • Raritan
  • H3C HDM
  • Fujitsu

Potential Impact

If exploited, these security gaps empower attackers to bypass existing defenses, granting them the ability to access, manipulate, or completely disable the affected BMCs. Ultimately, this level of compromise provides a formidable stepping stone for establishing persistence and moving laterally throughout a managed enterprise network.

Mitigation and Workarounds

Organizations must remain vigilant by closely monitoring vendor security advisories and enforcing a strict, formal patching cadence across all BMC hardware. As embargoes lift and official CVEs drop, runZero will automatically identify and flag these specific vulnerabilities within our platform.

To secure unpatched systems immediately:

  • Restrict management interface access strictly to trusted internal IP addresses or specific subnets.
  • Sever the interface’s connection to the public Internet completely.
  • If total isolation is impossible, ensure that all access is funneled through a secure VPN or an isolated, out-of-band management network.
  • Ramp up logging and monitoring on any active management pathways.

Hunting for Vulnerable Assets in runZero

You can proactively identify potentially exposed systems in your environment. Simply navigate to your Asset Inventory and apply the following search query:

(protocol:ipmi OR type:=BMC) AND (
hw:=OpenBMC OR
hw:=”Super Micro IPMI” OR
hw:=”HP% iLO%” OR
hw:=”Dell iDRAC%” OR
hw:=”AMI MegaRAC” OR
(hw:=”Raritan%” AND type:=”Power Device”) OR
hw:=”H3C HDM” OR
hw:=”Fujitsu%”
)

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Discover more from Version 2 Limited

Subscribe now to keep reading and get access to the full archive.

Continue reading