CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-6693 | Hard-Coded Encryption Key in Fortinet FortiOS Configuration Backups FortiOS encrypts sensitive data inside configuration backup files using a hard-coded cryptographic key, meaning anyone who knows that fixed key can decrypt the data. An attacker who obtains a FortiOS configuration backup file - whether stored locally, transferred over the network, or held in a central backup repository - can decipher the protected contents offline without touching the firewall itself. The exposed data includes non-administrator user passwords, private key passphrases, and the High Availability password (when set), giving attackers credentials that can be reused for further access; CISA notes known ransomware use. Organizations running affected Fortinet FortiOS releases that create, store, or transfer configuration backups are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-06-25 with ransomware exploitation reported, and EPSS puts the 30-day exploitation probability at 5.6% (92nd percentile); no public PoC is known. Do: Inventory FortiOS deployments and locate all configuration backup files, including copies moved off-box to TFTP servers or central backup repositories, and restrict who can read them. Rotate exposed non-administrator user passwords, private-key passphrases, and High Availability passwords, since the hard-coded key means any accessible backup should be treated as plaintext. Upgrade FortiOS to a fixed release per Fortinet's security advisory, apply mitigations per vendor instructions or BOD 22-01 guidance for cloud services, and check logs for evidence that backup files were accessed or exfiltrated. | 6.5 | 6% | KEV ransomware |
| massmillions of FortiGate/FortiOS installations worldwide, with hundreds of thousands of FortiOS devices visible in public internet scans | |
| CVE-2024-0769 | Unauthenticated Path Traversal in D-Link DIR-859 Router (hedwig.cgi) D-Link DIR-859 routers running firmware 1.06B01 contain a critical path traversal flaw (CWE-22, CVSS 9.8) in the HTTP POST request handler of /hedwig.cgi. An unauthenticated remote attacker can manipulate the 'service' parameter with a directory-traversal path (e.g., ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml) to access files outside the intended location. Given the critical rating with high confidentiality, integrity, and availability impacts, successful exploitation can expose sensitive router configuration (potentially including credentials) and lead to full device compromise. Only DIR-859 units still in service are affected: D-Link has confirmed the product is end-of-life, so no patched firmware is available. Exploitation is now in the wild — CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-25, EPSS puts 30-day exploitation probability at 82.7%, a public proof-of-concept exists, and news reports indicate threat actors are actively exploiting D-Link DIR-series flaws. Do: Because the DIR-859 is end-of-life, there is no firmware fix — replace the router with a currently supported model, as the vendor recommends. If replacement is not immediate, minimize exposure by disabling remote/WAN management access to the device and any port-forwarding or UPnP rules that expose the web interface, and monitor for exploitation attempts against /hedwig.cgi. Federal agencies must follow CISA BOD 22-01 and remediate by the assigned KEV due date. | 9.8 | 83% | KEV PoC |
| Unknown; plausibly tens of thousands of DIR-859 units remain deployed, with an internet-exposed subset likely in the thousands | |
| CVE-2024-54085 | Remote Authentication Bypass by Spoofing in AMI MegaRAC SP-X BMC CVE-2024-54085 is an authentication bypass by spoofing (CWE-290) in the AMI MegaRac SP-X baseboard management controller (BMC), allowing a remote attacker to impersonate an authorized client through the Redfish Host Interface without valid credentials. The flaw is network-exploitable with low attack complexity, no required privileges, and no user interaction, which is why it carries a maximum CVSS 4.0 score of 10.0. A successful attacker gains full BMC-level control of the host, with high impact to confidentiality, integrity, and availability; published coverage describes remote server takeover, including the ability to run attacker code and even brick servers. Anyone running servers or appliances built on the MegaRAC SP-X BMC is affected, including NetApp FAS (H300S, H500S, H700S), HCI (H410S, H410C), and StorageGRID (SG6160, SGF6112, SG110, SG1100) appliances that embed this BMC. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-25, and EPSS assigns a 60.7% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known. Do: Apply the patched MegaRAC SP-X firmware distributed by your server OEM, or the updated BMC firmware referenced in NetApp's security advisory for the affected FAS, HCI, and StorageGRID appliance models (fixed version numbers were not included in this data set). Until patched, restrict access to BMC management interfaces (including Redfish/IPMI) by isolating them from the internet and untrusted network segments, and scan for externally exposed BMC ports. As the flaw is on CISA's KEV catalog (added 2025-06-25), federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. | 10.0 | 61% | KEV |
| massHundreds of thousands to millions of server BMCs (AMI's MegaRAC SP-X is embedded in server lines from many OEMs, and public internet-wide scans have repeatedly… |
Full article712 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 26, 2025Vulnerability / Firmware Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three security flaws, each impacting AMI MegaRAC, D-Link DIR-859 router, and Fortinet FortiOS, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The list of vulnerabilities is as follows -
- CVE-2024-54085 (CVSS score: 10.0) - An authentication bypass by spoofing vulnerability in the Redfish Host Interface of AMI MegaRAC SPx that could allow a remote attacker to take control
- CVE-2024-0769 (CVSS score: 5.3) - A path traversal vulnerability in D-Link DIR-859 routers that allows for privilege escalation and unauthorized control (Unpatched)
- CVE-2019-6693 (CVSS score: 4.2) - A hard-coded cryptographic key vulnerability in FortiOS, FortiManager and FortiAnalyzer that's used to encrypt password data in CLI configuration, potentially allowing an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data
Firmware security company Eclypsium, which disclosed CVE-2024-54085 earlier this year, said the flaw could be exploited to carry out a wide-range of malicious actions, including deploying malware and tampering with device firmware.
There are currently no details on how the shortcoming is being weaponized in the wild, who may be exploiting it, and the scale of the attacks. When reached for comment, Eclypsium said there has been no public attribution for these attacks, but suspected China-nexus threat actors such as Volt Typhoon, Salt Typhoon, Flax Typhoon, APT31, APT41, and Velvet Ant as "likely candidates."
Some of these state-sponsored groups, it said, have been implicated in campaigns that revolve around the use of firmware backdoors and Unified Extensible Firmware Interface (UEFI) implants for persistence and stealth.
"The vulnerability can be exploited by making an HTTP POST request to a vulnerable BMC device," Paul Asadoorian, Principal Security Researcher at Eclypsium, told The Hacker News. "The example exploit code was published, allowing a remote attacker to create an administrator account on the BMC without prior authentication."
"To our knowledge, how the attackers used the exploit in the wild, post-exploitation details, IoCs, and malware samples have not been made publicly available."
Some of the post-exploitation actions that an attacker can carry out post a BMC compromise are listed below -
- Attackers could chain multiple BMC exploits to implant malicious code directly into the BMC's firmware, making their presence extremely difficult to detect and allowing them to survive OS reinstalls or even disk replacements.
- By operating below the OS, attackers can evade endpoint protection, logging, and most traditional security tools.
- With BMC access, attackers can remotely power on or off, reboot, or reimage the server, regardless of the primary operating system's state.
- Attackers can scrape credentials stored on the system, including those used for remote management, and use the BMC as a launchpad to move laterally within the network
- BMCs often have access to system memory and network interfaces, enabling attackers to sniff sensitive data or exfiltrate information without detection
- Attackers with BMC access can intentionally corrupt firmware, rendering servers unbootable and causing significant operational disruption
Eclypsium also noted that there are about 2,000 exposed AMI MegaRAC BMCs accessible on the internet, with many more accessible internally. Companies known to use the affected product line include AMD, Ampere Computing, ASRock, ARM, Fujitsu, Gigabyte, Huawei, Nvidia, Supermicro, and Qualcomm.
The exploitation of CVE-2024-0769 was revealed by threat intelligence firm GreyNoise exactly a year ago as part of a campaign designed to dump account names, passwords, groups, and descriptions for all users of the device.
It's worth noting that D-Link DIR-859 routers have reached end-of-life (EoL) as of December 2020, meaning the vulnerability will remain unpatched on these devices. Users are advised to retire and replace the product.
As for the abuse of CVE-2019-6693, multiple security vendors have reported that threat actors linked to the Akira ransomware scheme have leveraged the vulnerability to obtain initial access to target networks.
In light of the active exploitation of these flaws, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary mitigations by July 16, 2025, to secure their networks.
(The story was updated after publication to include a response from Eclypsium.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/06/cisa-adds-3-flaws-to-kev-catalog.html