HD Moore's runZero scan found 86,000 baseboard management controllers reachable from the open internet, 54% carrying at least one critical flaw, and 75,000 still vulnerable to a bug disclosed in 2013.
Read the full story: 86,000 Server BMCs Sit Exposed, Half Critically Flawed →
Transcript
Underneath every enterprise server sits a second computer you probably do not patch. It has its own processor, its own firmware, and its own network port, and it stays powered when the machine is off. It is called a baseboard management controller. It can power cycle the host, reflash the BIOS, and mount virtual media. At Black Hat this week, H D Moore, the person who created Metasploit, presented a scan of them. Eighty six thousand are reachable from the open internet, and fifty four percent carry at least one critical vulnerability. Seventy five thousand are still vulnerable to a flaw disclosed in twenty thirteen. Moore is the one who disclosed it. Here is why it matters. Reinstall the operating system and the controller is untouched. Your endpoint security runs inside the OS, which the controller can reboot and watch. Most organizations have never counted how many they own.