peter bassill · operator
$ cve CVE-2024-54085 JSON

CVE-2024-54085 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 60.7% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-07-16.

Description

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS60.75% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-290
On CISA KEVyes — remediate by 2025-07-16
Public exploitnone known
Published2025-03-11
Last modified2026-06-17

CISA KEV

NameAMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Added2025-06-25
Due2025-07-16
Vendor / productAMI / MegaRAC SPx
Ransomware usenone reported

Affected (19)

VendorProduct
amimegarac sp-x
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware
netappsg110
netappsg110 firmware
netappsg1100
netappsg1100 firmware
netappsg6160
netappsg6160 firmware
netappsgf6112
netappsgf6112 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD