CVE-2024-54085
KEVmassRemote Authentication Bypass by Spoofing in AMI MegaRAC SP-X BMC
CISA: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
CVE-2024-54085 is an authentication bypass by spoofing (CWE-290) in the AMI MegaRac SP-X baseboard management controller (BMC), allowing a remote attacker to impersonate an authorized client through the Redfish Host Interface without valid credentials. The flaw is network-exploitable with low attack complexity, no required privileges, and no user interaction, which is why it carries a maximum CVSS 4.0 score of 10.0. A successful attacker gains full BMC-level control of the host, with high impact to confidentiality, integrity, and availability; published coverage describes remote server takeover, including the ability to run attacker code and even brick servers. Anyone running servers or appliances built on the MegaRAC SP-X BMC is affected, including NetApp FAS (H300S, H500S, H700S), HCI (H410S, H410C), and StorageGRID (SG6160, SGF6112, SG110, SG1100) appliances that embed this BMC. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-25, and EPSS assigns a 60.7% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known.
What to do: Apply the patched MegaRAC SP-X firmware distributed by your server OEM, or the updated BMC firmware referenced in NetApp's security advisory for the affected FAS, HCI, and StorageGRID appliance models (fixed version numbers were not included in this data set). Until patched, restrict access to BMC management interfaces (including Redfish/IPMI) by isolating them from the internet and untrusted network segments, and scan for externally exposed BMC ports. As the flaw is on CISA's KEV catalog (added 2025-06-25), federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.
| AMI MegaRAC SP-X (BMC firmware) | — |
| NetApp H300S firmware (FAS appliance with embedded AMI MegaRAC BMC) | — |
| NetApp H500S firmware (FAS appliance with embedded AMI MegaRAC BMC) | — |
| NetApp H700S firmware (FAS appliance with embedded AMI MegaRAC BMC) | — |
| NetApp H410S firmware (HCI appliance with embedded AMI MegaRAC BMC) | — |
| NetApp H410C firmware (HCI appliance with embedded AMI MegaRAC BMC) | — |
| NetApp SG6160 firmware (StorageGRID appliance with embedded AMI MegaRAC BMC) | — |
| NetApp SGF6112 firmware (StorageGRID appliance with embedded AMI MegaRAC BMC) | — |
| NetApp SG110 firmware (StorageGRID appliance with embedded AMI MegaRAC BMC) | — |
| NetApp SG1100 firmware (StorageGRID appliance with embedded AMI MegaRAC BMC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
- Affected
- AMI MegaRAC SPx
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- aminetapp
- Products
- megarac sp-x, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware, sg6160 firmware, sgf6112 firmware, sg110 firmware, sg1100 firmware
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X