HomeSecuritySupermicro BMC Bug: "Virtual USBs" compromise corporate servers

Supermicro BMC Bug: “Virtual USBs” compromise corporate servers

It turns out that a hacker could exploit flaws in a type of remote management device to connect as many “virtual” drives as they want. And the same type of attack can turn almost any USB into a virtual trojan horse.

Supermicro

In new findings presented at the Open Source Firmware conference in Silicon Valley on Tuesday, researchers from security firm Eclypsium detailed vulnerabilities in a number of Supermicro BMCs, which are specialized processors that are installed on server motherboards to give system administrators specialized management capabilities at the hardware level. This is useful when administrators need to do things like load old software onto a server from a CD or upgrade an operating system from an image on an external hard drive. BMCs facilitate the entire process without having to physically connect anything to the server itself. The server will simply think that a device is directly connected.

The researchers found, however, that the BMCs on the Supermicro X9, X10, and X11 platforms contain flaws that could be exploited by an attacker. A hacker could potentially wipe data on a thumb drive or external hard drive, replace a server’s operating system with a malicious one, or even take the server offline. Attackers could also exploit the flaw once they have access to a corporate network to gain deeper control over systems. But they could launch these attacks remotely if organizations leave their BMCs exposed online — like the more than 47,000 exposed BMCs that the researchers identified in a recent scan.

“The problem with hacker intrusions is that physical presence is a significant challenge. However, in our case we have the equivalent of physical presence,” says Rick Altherr, principal engineer at Eclypsium. “There are really endless possibilities with this, and BMCs are very common devices.”

If an administrator wanted to essentially plug a USB device into a server, they would use a web-based “virtual media” management application from their laptop or other device to essentially call into the BMC and take advantage of hardware. Eclypsium researchers found, however, that the authentication systems on systems running these virtual media protocols are vulnerable to numerous and different types of attacks.

The system can store legitimate administation credentials, for example, sometimes allowing the next user to enter any username and password and gain access. Altherr said he found this bug very reliable in testing, but even if the open window is suddenly closed, the hacker can still try the default Supermicro credentials that are often not changed. And for a hacker already on the network and wanting to get to the BMC, there is another option to get the credentials by intercepting traffic between the web application and the BMC, because the connection is only protected by relatively weak encryption.

Researchers disclosed the flaws to Supermicro in June, and the company has issued firmware updates for all affected BMCs. Eclypsium CEO Yuriy Bulygin notes, however, that like many of the company's devices, BMCs are often slow to receive firmware updates in practice. As a result, it will likely take time for patches to reach vulnerable servers.

“We would like to thank the researchers who identified the BMC Virtual Media vulnerability,” a Supermicro spokesperson said in a statement. “New versions of the BMC software address these vulnerabilities.”

In an October 2018 investigation, Bloomberg Businessweek claimed that many Supermicro motherboards around the world had been compromised with a backdoor installed by the Chinese military. Supermicro and other tech giants that use the company's servers deny the validity of the report.

Eclypsium researchers hope to raise awareness of the potential exposures that can come from BMC appliances in general, as they are privileged devices intended for remote use. They provide a genuine service to network administrators and can help administrators make security upgrades. But, like any such tool, these features can also be exploited by hackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS