Security

Firmware: The Part Nobody Updates

Everyone updates the operating system and applications, but firmware remains the forgotten layer of infrastructure. BIOS, BMC, RAID controllers, NICs, SSDs: every component has its own firmware, and each one can become an attack vector if left unmanaged.

business EasyDataHost calendar_today April 9, 2026 schedule 8 min read

Any systems administrator knows they must keep the operating system up to date. Kernel security patches, Apache or Nginx updates, database upgrades: all of that is part of routine maintenance. The tools are there, the processes are defined, and security advisories arrive punctually by email. But there is one layer that is systematically left out of that cycle: firmware.

Firmware is the software that runs on the hardware before the operating system even boots. It lives in the BIOS/UEFI, in the remote management controller (BMC, iLO, iDRAC), in the RAID controller, in network cards, in SSDs and HDDs, and even in network switches and routers. It is the foundation on which everything else runs, and yet it is the last thing that gets updated -- if it ever gets updated at all.

This article explains what firmware actually is in a server, why almost nobody updates it, the specific risks of not doing so, real-world cases of critical vulnerabilities, and best practices for managing it professionally -- especially in environments where security and regulatory compliance are mandatory.

What Is Firmware in a Server

Firmware is a program stored in non-volatile memory (flash, EEPROM) that controls the low-level behaviour of a hardware component. Unlike software installed on the operating system, firmware lives inside the device itself and runs independently. A typical server has multiple firmwares operating simultaneously:

  • developer_board BIOS/UEFI: the motherboard firmware. It initialises hardware, runs the POST (Power-On Self-Test), configures RAM, detects storage devices and hands control over to the operating system bootloader. Vulnerabilities in UEFI can allow persistent rootkits that survive a complete OS reinstallation.
  • settings_remote BMC / iLO / iDRAC: the remote management controller (Baseboard Management Controller). It operates with its own processor, memory and network stack, completely independent of the main OS. It allows powering on, shutting down, monitoring and remotely accessing the server console. A vulnerability in the BMC is equivalent to having physical access to the server.
  • storage RAID controller: manages disk arrays (RAID 0, 1, 5, 6, 10). Its firmware controls the write cache, degraded array rebuilding and error detection. A bug in the RAID controller firmware can cause silent data corruption.
  • lan NIC (network interface card): 10/25/100 GbE network cards have their own firmware managing offloading, SR-IOV, RDMA and advanced network features. Vulnerabilities in NIC firmware can enable DMA attacks or OS firewall bypass.
  • hard_drive_2 SSD / HDD: every drive has firmware that manages wear levelling, bad block management, internal cache and garbage collection. Bugs in SSD firmware can cause total data loss or severe performance degradation.
  • router Switches and routers: network equipment firmware controls routing, switching, VLANs, ACLs and all network functions. A vulnerability here can compromise all data centre traffic.

Why Nobody Updates Firmware

The reality is that most production servers run with factory firmware, or at best the version that was current when the operating system was installed years ago. The reasons are predictable but no less problematic:

  • do_not_disturb "If it works, don't touch it": the most widespread and most dangerous mentality. Firmware is so far from the application layer that updating it feels like an unnecessary risk. The problem is that this logic completely ignores the security aspect: a BMC with five-year-old firmware has known, documented vulnerabilities with public exploits.
  • warning Fear of bricking: a failed firmware update can render a component unusable. Unlike a software package that can be uninstalled, an interrupted firmware flash may require physical intervention or an RMA of the hardware. This fear, while understandable, is mitigated by proper procedures and modern hardware with rollback mechanisms.
  • restart_alt Requires reboot or downtime: most firmware updates require restarting the server, and in many cases restarting the specific component (which means rebooting the entire server). In production environments without redundancy, this means planned downtime, maintenance windows and coordination with business teams.
  • handyman Lack of automated tools: while OS software is updated with apt, yum or Windows Update, firmware requires vendor-specific tools (Dell DSU, HPE SUM, Lenovo OneCLI) that are not always integrated into standard workflows. Many administrators do not even know these tools exist.
  • visibility_off Lack of visibility: there is no equivalent of "apt list --upgradable" for firmware. Knowing which firmware version each component is running and whether updates are available requires manual effort that in practice nobody performs systematically.

Real Risks of Not Updating Firmware

Not updating firmware is not simply "skipping an improvement": it means maintaining known vulnerabilities, documented performance bugs and compatibility issues that can manifest at the worst possible time. The specific risks include:

  • shield Security vulnerabilities: CVEs in BMC, UEFI and NIC firmware are frequent and severe. An attacker who exploits a BMC vulnerability gains total control of the server, regardless of the operating system, firewall or antivirus. UEFI rootkit vulnerabilities survive OS reinstallations and disk formatting, as documented in our security policy.
  • speed Performance bugs: manufacturers like Intel, Samsung and Micron regularly release SSD firmware updates that fix performance bugs, latency issues and garbage collection errors. A server with outdated SSD firmware can be performing 30-40% below its real capacity.
  • database Data corruption: some of the most critical SSD firmware bugs can cause total data loss. This is not a theoretical risk: there are documented cases of specific SSD models that failed after a precise number of operating hours if a firmware update was not applied, as we also discuss in our article about NAS misuse.
  • sync_problem Compatibility issues: upgrading the OS or drivers without updating firmware can create incompatibilities. A new kernel may not work correctly with old NIC firmware, causing intermittent disconnections or throughput degradation.
  • support_agent Loss of vendor support: when a ticket is opened with Dell, HPE or Lenovo, the first thing they check is the firmware version. If it is not up to date, the vendor may require the update before investigating the issue. In critical environments, this delays incident resolution precisely when urgency is greatest.

Key fact:

According to an Eclypsium study (2023), 32% of organisations have experienced a firmware-related security incident in the last two years. Compromised firmware is especially dangerous because it operates below the operating system and is invisible to most conventional security tools.

Real Cases: When Firmware Fails

The risk of not updating firmware is not theoretical. There are documented incidents that have affected thousands of servers worldwide:

  • error Intel SSD DC S3500/S3700 (2017): a firmware bug caused SSDs to stop working completely after 1,700 hours of cumulative use (about 70 days). Intel released a corrective firmware, but servers that did not apply it suffered total data loss. Thousands of data centre operators were affected.
  • error HPE iLO vulnerabilities (CVE-2017-12542): a critical vulnerability in iLO 4 firmware allowed authentication bypass with a simple HTTP request. An attacker with access to the management network could gain total server control without credentials. The vulnerability had a CVSS score of 9.8 (critical).
  • error Spectre/Meltdown (2018): although known as CPU vulnerabilities, their complete mitigation required microcode updates (processor firmware) in addition to OS patches. Servers that only applied kernel patches without updating the microcode remained partially exposed. Modern ransomware exploits these kinds of gaps.
  • error Dell iDRAC CVEs (2020-2024): multiple critical vulnerabilities in Dell iDRAC 7/8/9 have allowed remote code execution, privilege escalation and denial of service. Dell has released patches for each one, but servers with outdated firmware remain vulnerable years later.
  • error Samsung SSD 980 Pro (2022): a firmware bug in the consumer model (also used in some NAS units and workstations) caused progressive performance degradation and eventually data loss. Samsung released a corrective firmware, but many users never applied it due to lack of awareness.

Types of Firmware in a Server

The following table summarises the main types of firmware found in a typical dedicated server, their recommended update frequency, the risk level of not updating and the usual update method:

Component Frequency Risk Method
BIOS/UEFI Quarterly or on CVE Critical DSU / SUM / flashrom + reboot
BMC / iLO / iDRAC Quarterly or on CVE Critical Web UI / CLI / DSU / SUM (no OS reboot)
RAID controller Biannually High StorCLI / DSU / SUM + reboot
NIC (network card) Biannually or on CVE High ethtool / nvmupdate / DSU + reboot
SSD / NVMe On vendor advisory Critical fwupd / vendor CLI + reboot
HDD Annually or on advisory Medium Vendor CLI + reboot
Switch / Router Quarterly High Vendor CLI / Web UI

Best Practices for Managing Firmware

Managing firmware professionally is not optional: it is a fundamental part of the hardware lifecycle and the organisation's security posture. These are the practices every operations team should implement:

  • inventory Version inventory: maintain an up-to-date record of the firmware version of every component in every server. Tools such as Dell DSU (Dell System Update), HPE SUM (Smart Update Manager) or Lenovo OneCLI can generate these inventories automatically.
  • cycle Regular audit cycle: establish a quarterly review cycle for available firmware. Subscribe to vendor security bulletins (Dell Security Advisories, HPE Security Bulletins, Intel Security Center) to receive alerts for CVEs requiring urgent updates.
  • science Test in staging first: never apply a firmware update directly in production. Test first on a staging or pre-production server with the same hardware configuration. Verify that the server boots correctly, that all components function and that performance has not degraded.
  • description Document every update: record which version was applied, on what date, on which servers and whether any incidents occurred during the process. This documentation is essential for security audits and for rollback in case of problems.
  • build Use vendor tools: Dell DSU allows updating all firmware on a Dell server with a single command. HPE SUM does the equivalent for HPE ProLiant servers. On Linux, the fwupd project integrates firmware updates from multiple vendors. These tools drastically reduce the risk of human error.
  • event Scheduled maintenance windows: programme quarterly maintenance windows specifically for firmware updates. Coordinate with business teams, migrate critical workloads to other servers where possible, and execute updates in a controlled manner.

Firmware and Regulatory Compliance

The most demanding security regulations make no distinction between software and firmware when discussing patch management. ISO 27001 (control A.8.8 -- Management of technical vulnerabilities) requires organisations to keep all infrastructure components up to date, including firmware. Spain's Esquema Nacional de Seguridad (ENS) has equivalent requirements.

In practice, this means that if your organisation is ISO 27001 certified or must comply with the ENS, you need a documented firmware management process that includes inventory, risk assessment, update planning and record keeping. Not updating server firmware is a common finding in security audits that can put your certification at risk.

EasyDataHost maintains firmware management processes aligned with compliance requirements from ISO 27001 and ENS, ensuring all infrastructure components are up to date and documented.

Important for compliance:

ISO 27001 and ENS require patch management that includes firmware. A server with outdated firmware is an audit finding that can compromise your organisation's certification.

Let the Experts Handle It

If managing firmware feels overwhelming, or you simply do not have the internal resources to do it systematically, the most practical solution is to delegate to a managed services provider. A team specialised in data centre hardware has the experience, tools and procedures to update firmware safely and without impacting production.

Managed firmware services include: automated version inventory, security bulletin monitoring, update planning, execution during coordinated maintenance windows, comprehensive documentation and incident support. It is the difference between "we hope nothing happens" and "we have a process that ensures nothing will happen".

How EasyDataHost Manages Firmware

At EasyDataHost, firmware management is an integral part of our infrastructure maintenance cycle. All enterprise servers and SME dedicated servers receive proactive firmware updates.

  • check_circle Quarterly audit: every quarter we review the firmware versions of all components in every server and compare them against the vendor's available releases.
  • check_circle Immediate CVE response: when a critical CVE affecting firmware components in our infrastructure is published, the update is planned within a maximum of 72 hours.
  • check_circle Prior testing: all firmware updates are tested on staging hardware before being applied in production.
  • check_circle Full documentation: every update is recorded with version, date, server and outcome, available for audits.

Conclusion

Firmware is the invisible foundation on which an entire server infrastructure operates. Ignoring it is not a valid strategy: it means accepting known vulnerabilities, documented performance bugs and data loss risks that are completely preventable. Proactive firmware management is not a luxury -- it is an operational necessity and a compliance requirement.

  • arrow_right Firmware exists in every server component: BIOS, BMC, RAID, NIC, SSD, switches.
  • arrow_right Not updating it exposes you to critical vulnerabilities, performance bugs and data loss.
  • arrow_right Real-world cases like Intel SSD, iLO CVEs and Spectre/Meltdown demonstrate the actual impact.
  • arrow_right ISO 27001 and ENS require patch management that includes firmware.
  • arrow_right EasyDataHost manages firmware proactively with quarterly audits and immediate CVE response.

If you need servers with professional firmware management included, or want us to handle firmware updates for your existing infrastructure, contact our team to design a maintenance plan tailored to your needs.

Firmware Security Servers Compliance Patch Management
system_update

Servers with firmware always up to date

EasyDataHost manages firmware proactively: quarterly audits, immediate vulnerability response, prior testing and full documentation for compliance.