← Zuruck zu CVEs
CVE-2024-54085
CRITICALCISA KEV9.8
Beschreibung
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/11/2025
Zuletzt geandert11/5/2025
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerAMI
ProduktMegaRAC SPx
SchwachstellennameAMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
KEV Aufnahmedatum2025-06-25
Behebungsfrist2025-07-16
Ransomware-NutzungUnknown
Betroffene Produkte
ami:megarac_sp-xnetapp:h300snetapp:h300s_firmwarenetapp:h410cnetapp:h410c_firmwarenetapp:h410snetapp:h410s_firmwarenetapp:h500snetapp:h500s_firmwarenetapp:h700snetapp:h700s_firmwarenetapp:sg110netapp:sg1100netapp:sg1100_firmwarenetapp:sg110_firmwarenetapp:sg6160netapp:sg6160_firmwarenetapp:sgf6112netapp:sgf6112_firmware
Schwachen (CWE)
CWE-290
Referenzen
https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf(biossecurity@ami.com)
https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/(af854a3a-2127-422b-91ae-364da2661108)
https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20250328-0003/(af854a3a-2127-422b-91ae-364da2661108)
https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/(af854a3a-2127-422b-91ae-364da2661108)
https://www.networkworld.com/article/4013368/ami-megarac-authentication-bypass-flaw-is-being-exploitated-cisa-warns.html(af854a3a-2127-422b-91ae-364da2661108)
https://nvd.nist.gov/vuln/detail/CVE-2024-54085(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://security.netapp.com/advisory/ntap-20250328-0003/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-54085(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.