Researchers find that weaknesses in Supermicro hardware would let an attacker leave a persistent and hidden backdoor on IBM's cloud “bare-metal” servers
Other providers of bare-metal cloud computing might also be vulnerable to BMC hack. — More than five years …
Context & Ripple Effects
This finding lands mid-arc in a long Supermicro security saga: the company's firmware portal was breached in 2015, with customers including Facebook downloading malware from it, and US investigators would later allege Supermicro server hardware was tampered with as late as 2018. What this research adds is the mechanism — the BMC management chip, present on bare-metal servers across providers, as the place where an attacker could hide a backdoor that survives reimaging.
The significance for IBM specifically is that its bare-metal cloud offering hands tenants physical servers, so a compromised BMC sits below every software-level control the customer can apply. Months later, researchers found related motherboard flaws allowing remote virtual USB drives, with 47,000+ exposed devices online even after patching — evidence that the attack surface persisted beyond any single fix.
First-order effects
- IBM's bare-metal cloud customers face a threat model where a hidden BMC-resident backdoor survives OS reinstalls, and the researchers note other bare-metal providers running Supermicro hardware are potentially exposed to the same technique.
Second-order effects
- Every provider selling single-tenant servers on Supermicro boards is pushed into auditing and patching BMC firmware rather than just host software, since the September 2019 virtual-USB findings showed tens of thousands of devices remained reachable after fixes.
Third-order effects
- If hardware-level compromise keeps recurring — culminating in the later allegations of tampered Supermicro servers with backdoor chips — procurement shifts toward firmware attestation and supplier diversification, making board-level trust a purchasing criterion rather than an assumption.
The trend: Server security is moving up the stack from OS patching to hardware and firmware trust, as BMC-class management silicon becomes the preferred persistence point for attackers.