Back to overview

CVE-2024-54085

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 4.0
Description
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

Metadata

CVE ID
CVE-2024-54085
State
PUBLISHED
Assigner
AMI
Reserved
2024-11-28 05:10 UTC
Published
2025-03-11 14:00 UTC
Last updated
2026-02-26 19:09 UTC
Primary CWE
CWE-290
CWE-290 Authentication Bypass by Spoofing
Vendor / Product
AMI / MegaRAC-SPx
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Vendor
AMI
Product
MegaRAC SPx
Added to KEV
2025-06-25
Due date
2025-07-16
Ransomware
Not known
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Affected products (1)
VendorProductPlatformVersions
AMI MegaRAC-SPx 12.0 < 12.7, 13.0 < 13.5
Weakness (CWE)
CWESourceDescription
CWE-290 cna CWE-290 Authentication Bypass by Spoofing
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview