CRITICAL

CVE-2024-54085

Ami Megarac Sp X 2025-03-11 CVSS v3.1
CVSS
9.8
KEV

Description

AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerability may lead to a loss of confidentiality, integrity, and/or
availability.

Summary dbcve.org

AMI MegaRAC SPx BMC firmware contains an authentication bypass vulnerability in the Redfish Host Interface service. An unauthenticated remote attacker can exploit this to bypass authentication mechanisms and gain administrative access to the BMC, potentially controlling all hardware management functions including server power, firmware, and sensor data.

Mitigation

Apply the vendor-supplied firmware patch for MegaRAC SPx that addresses this Redfish authentication bypass. If a patch is unavailable, consider disabling the Redfish Host Interface or implementing network segmentation/firewall rules to restrict BMC access to trusted management networks only.

Weakness (CWE)

CWE-290

EPSS Score

60.75%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE