CVE-2024-54085 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 60.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2025-07-16.
Description
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 60.75% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | yes — remediate by 2025-07-16 |
| Public exploit | none known |
| Published | 2025-03-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability |
|---|---|
| Added | 2025-06-25 |
| Due | 2025-07-16 |
| Vendor / product | AMI / MegaRAC SPx |
| Ransomware use | none reported |
Affected (19)
| Vendor | Product |
|---|---|
| ami | megarac sp-x |
| netapp | h300s |
| netapp | h300s firmware |
| netapp | h410c |
| netapp | h410c firmware |
| netapp | h410s |
| netapp | h410s firmware |
| netapp | h500s |
| netapp | h500s firmware |
| netapp | h700s |
| netapp | h700s firmware |
| netapp | sg110 |
| netapp | sg110 firmware |
| netapp | sg1100 |
| netapp | sg1100 firmware |
| netapp | sg6160 |
| netapp | sg6160 firmware |
| netapp | sgf6112 |
| netapp | sgf6112 firmware |
References
- https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf
- https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/
- https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/
- https://security.netapp.com/advisory/ntap-20250328-0003/
- https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/
- https://www.networkworld.com/article/4013368/ami-megarac-authentication-bypass-flaw-is-being-exploitated-cisa-warns.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-54085
- https://security.netapp.com/advisory/ntap-20250328-0003/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-54085
→ the Explorer · watch your stack · NVD