← Volver a CVEs
CVE-2024-54085
CRITICALCISA KEV9.8
Descripcion
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/11/2025
Ultima modificacion11/5/2025
Fuentekev
Avistamientos honeypot0
CISA KEV
VendedorAMI
ProductoMegaRAC SPx
Nombre vulnerabilidadAMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Fecha inclusion KEV2025-06-25
Fecha limite remediacion2025-07-16
Uso en ransomwareUnknown
Productos afectados
ami:megarac_sp-xnetapp:h300snetapp:h300s_firmwarenetapp:h410cnetapp:h410c_firmwarenetapp:h410snetapp:h410s_firmwarenetapp:h500snetapp:h500s_firmwarenetapp:h700snetapp:h700s_firmwarenetapp:sg110netapp:sg1100netapp:sg1100_firmwarenetapp:sg110_firmwarenetapp:sg6160netapp:sg6160_firmwarenetapp:sgf6112netapp:sgf6112_firmware
Debilidades (CWE)
CWE-290
Referencias
https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf(biossecurity@ami.com)
https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/(af854a3a-2127-422b-91ae-364da2661108)
https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20250328-0003/(af854a3a-2127-422b-91ae-364da2661108)
https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/(af854a3a-2127-422b-91ae-364da2661108)
https://www.networkworld.com/article/4013368/ami-megarac-authentication-bypass-flaw-is-being-exploitated-cisa-warns.html(af854a3a-2127-422b-91ae-364da2661108)
https://nvd.nist.gov/vuln/detail/CVE-2024-54085(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://security.netapp.com/advisory/ntap-20250328-0003/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-54085(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.