Sora Yazılım
Network security, server and software solutions from Türkiye

Server Firmware Update Guide: BIOS, iDRAC and iLO

In short: A server firmware update is the planned refresh of BIOS/UEFI, the management controller (BMC) such as iDRAC or iLO, and RAID, network card and drive firmware. Safe practice: keep an inventory, track vendor advisories and the CISA KEV catalogue, prioritise by risk, back up, test first and isolate the BMC on a management network.

Why does a server firmware update need its own process?

Because firmware runs beneath the operating system: a failed update can leave a server unable to boot, while an unpatched management controller remains a highly privileged entry point reachable over the network. NIST SP 800-193 (Platform Firmware Resiliency, May 2018) warns that a successful attack on platform firmware could render a system inoperable, perhaps permanently, and builds its guidance on three principles: protection, detection and recovery.

The most sensitive component is the baseboard management controller (BMC) on the motherboard. On Dell servers it is called iDRAC (Integrated Dell Remote Access Controller); on HPE servers it is iLO (Integrated Lights-Out). NIST SP 800-147B describes this service processor as highly privileged, often able to update firmware, change configuration settings and read system memory.

The risk is not theoretical. The CISA Known Exploited Vulnerabilities catalogue (KEV, version 2026.10.04) has listed CVE-2024-54085 for AMI MegaRAC SPx, a BMC firmware product line, since 25 June 2025, noting it could affect a component used by different products. CVE-2025-37164 for HPE OneView was added on 7 January 2026. For edge devices, see our article on firewall vulnerabilities and patch management.

How do you build a firmware inventory?

Record each server's model, serial number and every component's installed firmware version in one table. iDRAC and iLO expose these versions in their management interfaces and through Redfish, the DMTF server management standard; HPE's iLO documentation presents them as a "FirmwareInventory" collection.

NIST SP 800-40 Rev. 4 also recommends tracking who administers each asset, how it is managed, its network connectivity, its business importance and restrictions such as "can only be rebooted during a monthly maintenance outage". Grouping similar servers into one "maintenance group" lets you write a single plan per group.

ComponentWhy it mattersWhat to record
BMC (iDRAC / iLO)Network-reachable; can power the server on and off remotelyVersion, licence tier, IP address and VLAN, user accounts
BIOS / UEFIControls the boot chain and hardware settingsVersion, list of non-default settings
RAID / boot storage controllerAll data access passes through itFirmware version, compatibility with the OS driver
Network cards and drivesWhere performance and stability bugs surfaceModel, firmware version, dependent service
Power supply, CPLD/FPGAPer Dell, PSU updates are long and must not be interrupted; CPLD/FPGA goes aloneVersion, downtime the update requires

Which firmware update should come first?

Three questions set the priority: is the flaw actively exploited, where is the component reachable from, and how critical is the server? For the first, check the vendor advisory and the CISA KEV catalogue. NIST SP 800-40 Rev. 4 cites Binding Operational Directive 22-01, which gives US federal agencies two weeks for new KEV entries; others may use the catalogue voluntarily.

The same guide gives four example scenarios: routine patching, emergency patching, emergency mitigation before a patch exists, and unpatchable assets. The decision table below maps them to server firmware.

SituationScenarioRecommended action
Fix released; flaw in KEV or vendor reports active exploitationEmergency patchingTry one server first, then roll out quickly to all affected; restrict BMC access meanwhile
Flaw exploited, no fix yetEmergency mitigationLimit BMC access to the management network, disable the affected service, watch the advisory
High severity, no exploitation reportedExpedited routineSchedule for the next maintenance window
Bug fix or new feature, no security impactRoutineBundle into a periodic maintenance window
Out-of-support server, no new firmwareUnpatchable assetIsolate it, restrict access, plan replacement

To score updates, rate each low, medium or high on exploitation, exposure (high if the BMC is reachable from the internet or user network) and business impact; anything high on two or more goes first.

How do you prepare the maintenance window and rollback plan?

Size the window around components that need downtime, back up configurations and confirm beforehand whether you can return to the previous version. According to Dell's PowerEdge update article, every update except iDRAC requires downtime, and power supply updates can take 30 to 60 minutes and must not be interrupted.

Rollback is not always permitted. NIST SP 800-147B recommends that systems can prevent unauthorised rollback to an earlier BIOS version; whether administrators may authorise it depends on the platform. NIST SP 800-193 notes that some systems can recover corrupted firmware from a separate backup image, and HPE iLO can hold a "recovery install set" with the minimal firmware needed to make the server bootable.

  • BMC configuration backup: HPE recommends a backup each time you update iLO firmware; it restores only to the same hardware configuration, and security state and event logs are not restored.
  • BIOS and RAID settings: export or document anything that differs from defaults.
  • Data backup: test that the OS and data backups actually restore.
  • Package checks: download only from the vendor, read the release notes, verify integrity and signature; HPE components ship with a digital signature file (.compsig) for this.
  • Access: the remote console may drop, so arrange on-site hands in advance.

In what order and stages should updates be applied?

Across the fleet, go from test to non-critical to critical servers; within each server, follow the vendor's documented component order. NIST SP 800-40 Rev. 4 recommends a small "canary" group first. The UK NCSC adds that testing should not drag on: once updates are out, attackers can work out the patched flaw.

  1. Define the target version set (baseline) and read the prerequisites in the release notes.
  2. Apply it on a test server; check boot, RAID, networking and applications.
  3. Apply it to a few non-critical servers and monitor for an agreed period.
  4. Move to critical servers in the maintenance window; update cluster nodes one at a time.
  5. Follow the vendor's component order. Dell example: iDRAC, BIOS, CPLD/FPGA, then the rest; iDRAC, BIOS, power supply and CPLD/FPGA updates run alone with nothing else scheduled.
  6. If problems appear, halt the rollout and roll back or apply a temporary mitigation.

On HPE, components typically ship in SPP (Service Pack for ProLiant) bundles, and iLO can group updates into an ordered "install set" tied to a maintenance window. Dell's documentation states that iDRAC with Lifecycle Controller manages firmware updates remotely without agents.

If you would like help setting up the inventory, test plan and maintenance windows for your Dell or HPE servers, we can support the rollout. Get a Quote

What should you verify after the update?

Confirm that installed versions match the baseline, that the server and its services come up healthy and that event logs show no errors; then keep monitoring that this state holds. NIST SP 800-40 Rev. 4 recommends checking that patches are not uninstalled, that a vulnerable version is not restored from backup and that the device is not reset to factory defaults.

BMC logs are the evidence. HPE's documentation says the iLO Integrated Management Log records firmware flash actions and the Security Log records security configuration changes; when either is full, new events overwrite older ones. Forward them to a central log system, as described in our article on centralised log management.

Dell's Ansible module documentation shows that catalogue-based updates can first produce a report without applying anything; the feature requires an iDRAC Enterprise licence. Automating inventory, reporting and verification with Redfish and Ansible is part of our DevOps and infrastructure automation service.

How do you protect iDRAC and iLO on the network?

Put the BMC on a management network separate from the internet and user networks, reachable only by administrators; grant access through a jump host or VPN and log every administrative action. In the words of NIST SP 800-147B, the service processor "should be on a private LAN accessible only to system administrators"; the same document warns that management networks may be less vetted than data networks.

The NCSC guidance on administration interfaces lists a dedicated management network, a VPN limited to authenticated administrators and IP allow lists, noting that allow lists alone are weaker. It describes jump hosts as a central point for authentication and activity logging and recommends alarms whenever break-glass accounts are used.

  • If the BMC shares a host network port, put management traffic on its own VLAN; prefer a dedicated management port where possible.
  • Change or disable default credentials; use named accounts with least privilege instead of shared ones.
  • Disable protocols you do not use; for example, iLO lets you switch off legacy SNMPv1 separately.
  • Reach the interface only over encrypted connections and manage its certificates.

For identity-based admin access instead of VPN, see our ZTNA overview.

Server firmware update checklist

Use this list before, during and after each window; the last column says when an item is done.

PhaseCheckDone when
BeforeInventoryAll component versions are current in the table
BeforeAdvisory and KEV reviewRelevant flaws and vendor guidance are noted
BeforeBackupsBMC backup taken, BIOS/RAID settings recorded, data restore tested
BeforePackageVendor source, signature/integrity check, release notes read
BeforeRollbackDowngrade options and recovery path are known
DuringComponent orderVendor order followed; critical components one at a time
DuringPower and downtimeLong-running updates completed without interruption
AfterVersionInventory matches the baseline
AfterHealthEvent logs clean, services running
OngoingBMC accessManagement network only, accounts reviewed, logs centralised

When does outside support make sense?

Outside support makes sense when the server count grows, critical systems tolerate little downtime or warranty coverage becomes unclear. To make firmware tracking a recurring task, write it into a server maintenance agreement.

For servers whose warranty has ended, we compare the options in post-warranty server support: manufacturer or third party; confirm details such as firmware and parts access in the vendor's current documentation. Current firmware does not help if the operating system is out of support, so also see our Windows Server 2016 end-of-support migration plan.

Sora Yazılım provides selection, procurement, installation, support and server maintenance agreements for Dell PowerEdge servers and HPE ProLiant servers; scope is defined in the contract.

FAQ

Does an iDRAC or iLO update reboot the server?

Dell's PowerEdge article states that every update except iDRAC requires downtime; during an iDRAC update the management session drops while the controller restarts. HPE documentation says a BIOS update is activated when the server reboots. For iLO and other components, check each package's release notes and plan the window accordingly.

Can I roll back after a BIOS update?

Not always. NIST SP 800-147B recommends that servers can block unauthorised rollback to an earlier BIOS version, and whether an administrator may authorise a downgrade depends on the platform. Do not assume rollback: confirm the conditions with the vendor, back up your settings and test first.

How often should server firmware be updated?

There is no single correct interval. Bundle updates without security impact into periodic maintenance windows, and treat flaws listed in KEV or reported by the vendor as actively exploited as emergency patches. NIST SP 800-40 Rev. 4 suggests allowing flexibility for routine updates but enforcing installation once a defined grace period ends.

Is it safe to expose iDRAC or iLO to the internet?

It is not recommended. NIST SP 800-147B says the service processor should sit on a private, administrator-only network, and the NCSC advises protecting administration interfaces with a dedicated network, VPN and access restrictions. For remote access, use a VPN or jump host, keep accounts personal and log every session.

Do Dell and HPE use different update tools?

Yes; the concepts are similar but the tooling differs. On Dell, iDRAC with Lifecycle Controller works with update packages and catalogue-based repositories. On HPE, components ship in SPP bundles, and iLO offers a component repository, ordered install sets and maintenance windows. In a mixed fleet, follow each vendor's order and tools separately.

Can I have firmware updates carried out with outside support?

Yes. Inventory, test planning, execution in the maintenance window and BMC network separation can be run with a service provider, with scope and responsibilities written into the contract. To plan this for your Dell or HPE servers, contact us with your requirements and server count.

Conclusion

  • Firmware updates start with an inventory: version, owner and downtime constraints for every server and component.
  • Priority follows exploitation status, exposure and business impact; KEV-listed flaws fall under emergency patching.
  • Backups, package checks and rollback conditions are settled before the window; component order comes from the vendor.
  • Staged rollout, version checks and central logging complete the process; the BMC stays on a separate management network.

Sora Yazılım can cover firmware tracking, maintenance window planning and execution on Dell and HPE servers as part of a server maintenance agreement; scope is defined in the contract.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com

Sources

  1. NIST SP 800-193, Platform Firmware Resiliency Guidelines — NIST, May 2018. csrc.nist.gov (accessed 7 October 2026)
  2. NIST SP 800-147B, BIOS Protection Guidelines for Servers — NIST, August 2014. csrc.nist.gov (accessed 7 October 2026)
  3. NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning — NIST, April 2022. csrc.nist.gov (accessed 7 October 2026)
  4. Known Exploited Vulnerabilities Catalog, data file version 2026.10.04 — CISA. github.com/cisagov/kev-data (accessed 7 October 2026)
  5. AMI Security Advisory AMI-SA-2025003 — AMI, 13 March 2025. go.ami.com (accessed 7 October 2026)
  6. PowerEdge: How to update every Important Component, article 000333712 — Dell Technologies, last modified 12 June 2026. dell.com (accessed 7 October 2026)
  7. iDRAC-Redfish-Scripting README and OpenManage Ansible idrac_firmware documentation — Dell, GitHub. README, idrac_firmware (accessed 7 October 2026)
  8. iLO Backup and Restore, Software/Firmware update service, Log services, Network protocols — HPE Server Management Portal. Backup and Restore, update service, Log services, Network protocols (accessed 7 October 2026)
  9. Secure system administration: Protect your administration interfaces — NCSC. ncsc.gov.uk (accessed 7 October 2026)
  10. Keeping devices and software up to date — NCSC. ncsc.gov.uk (accessed 7 October 2026)
  11. MegaRAC (in the American Megatrends article) — Wikipedia. en.wikipedia.org (accessed 7 October 2026)

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical details were checked against the vendor and official sources linked in the text as of 7 October 2026.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support