CVE-2024-54085
Description
AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerability may lead to a loss of confidentiality, integrity, and/or
availability.
Summary dbcve.org
AMI MegaRAC SPx BMC firmware contains an authentication bypass vulnerability in the Redfish Host Interface service. An unauthenticated remote attacker can exploit this to bypass authentication mechanisms and gain administrative access to the BMC, potentially controlling all hardware management functions including server power, firmware, and sensor data.
Mitigation
Apply the vendor-supplied firmware patch for MegaRAC SPx that addresses this Redfish authentication bypass. If a patch is unavailable, consider disabling the Redfish Host Interface or implementing network segmentation/firewall rules to restrict BMC access to trusted management networks only.