Unmasking the Hidden Server: Out-of-Band Infrastructure Exposed
Baseboard Management Controllers (BMCs) represent a formidable, shadow attack surface embedded within conventional rack-mounted servers. Engineered with independent processors, isolated firmware, and dedicated network interfaces, these out-of-band (OOB) devices wield profound administrative control over their host machines. While the security community has scrutinized BMCs since at least 2013, the discourse intensified in August 2026 when HD Moore publicly spotlighted runZero’s deep-dive investigations into OOB infrastructure. Today initiates our structured rollout of vulnerability disclosures, following responsible coordination with affected hardware vendors and technology providers.
This initiative originated from a hybrid methodology: leveraging off-the-shelf AI tools and advanced prompting to surface hundreds of potential candidates. Refining this list to roughly 40 verified vulnerabilities, however, demanded exhaustive, traditional security research. This meant navigating the unglamorous realities of hardware hacking—extensive trial and error, reverse-engineering firmware virtualization, and enduring agonizingly slow physical reboots to validate exploits.
September 15, 2026 Update: Critical OpenBMC Vulnerabilities
Our inaugural disclosure targets the IPMI implementation within OpenBMC’s phosphor-net-ipmid component. These vulnerabilities were validated against both the OpenBMC reference architecture and downstream products deploying equivalent code bases, notably the NVIDIA BlueField-3 DPU BMC and the H3C HDM3.
It is crucial to highlight the pervasive white-labeling of OpenBMC. Without a robust Software Bill of Materials (SBOM), organizations remain dangerously unaware that OpenBMC is powering the “server inside their server,” regardless of the OEM branding stamped on the exterior chassis.
Vulnerability Mechanics & Exploit Chaining
| CVE Identifier | Vulnerability Type | Mechanism & Impact |
|---|---|---|
| CVE-2026-16141 | Authentication Bypass | Located in the RMCP+ session setup pathway. An attacker with network line-of-sight to IPMI can exploit a default key alongside a stale challenge state to establish an authenticated session without possessing the account password. This grants initial foothold access to the BMC’s IPMI interface. |
| CVE-2026-16140 | Privilege Escalation | An authenticated, low-privilege IPMI user can maliciously relabel an active session, mapping it to an enabled administrator account. This bypasses the need for the administrator’s password entirely. |
When weaponized in sequence, these two vulnerabilities can transform basic network access to an exposed IPMI service into total administrative dominance over the BMC. However, a successful exploit chain requires a “perfect storm” of prerequisites:
- The target must execute the vulnerable
phosphor-net-ipmidcode. - The IPMI service must be network-reachable.
- An enabled account name must be known or guessable by the attacker.
- For CVE-2026-16141, the stale challenge value must be predictable on that specific build (a factor heavily influenced by heap layout, allocator reuse, and precise session creation timing).
- For the privilege escalation (CVE-2026-16140), an administrator account must already be enabled on the device.
If these complex variables align, a threat actor gains the capacity to rewrite management configurations, manipulate core hardware functions, and infiltrate OOB console and storage mechanisms.
The Imperative of Deep Asset Discovery
Quantifying your exposure to these flaws is rarely straightforward. Standard server inventories typically record top-level vendor and model data, entirely missing the granular, embedded components driving the hardware. This highlights the critical necessity of comprehensive asset discovery.
A fundamental runZero query—such as (protocol:ipmi OR type:=BMC)—delivers immediate visibility into how many BMCs are actively listening for IPMI traffic across your environments. Following our Rapid Response release in August, running a broader IPMI diagnostic query is highly recommended. For teams with dedicated testing environments, runZero’s open-source oobscan toolchain is available to safely probe for these specific vulnerabilities.
Once assets are inventoried, runZero’s network topology and attack path mapping (introduced in version 4.9) become vital. These tools visualize the routing pathways to vulnerable devices, verifying whether your intended network segmentation holds up against reality. Fundamentally, IPMI interfaces should never be accessible from standard user subnets, production application segments, and certainly not the public internet.
Strategic Roadmap: The Month Ahead
This OpenBMC disclosure represents the first wave in a planned series of five technical releases. Over the ensuing weeks, culminating at the end of October, we will publish comprehensive technical details concerning vulnerabilities across several other vendor ecosystems (all of whom have been engaged via coordinated disclosure).
This post will serve as a living document, updated with links to our official advisories as subsequent disclosures go live. Our overarching mission is to eliminate informational asymmetry. The cybersecurity ecosystem remains fragile if deep attack surface knowledge is restricted to a minority of actors. We are committed to educating defenders, implementors, and researchers about the severe risks posed by untracked management interfaces. OOB devices like KVM emulators and BMCs are ubiquitous, frequently bleed outside of isolated management networks, and represent a critical blind spot that demands daily operational vigilance.
About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


