Actively exploited vulnerability gives extraordinary control over server fleets
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-54085 | Remote Authentication Bypass by Spoofing in AMI MegaRAC SP-X BMC CVE-2024-54085 is an authentication bypass by spoofing (CWE-290) in the AMI MegaRac SP-X baseboard management controller (BMC), allowing a remote attacker to impersonate an authorized client through the Redfish Host Interface without valid credentials. The flaw is network-exploitable with low attack complexity, no required privileges, and no user interaction, which is why it carries a maximum CVSS 4.0 score of 10.0. A successful attacker gains full BMC-level control of the host, with high impact to confidentiality, integrity, and availability; published coverage describes remote server takeover, including the ability to run attacker code and even brick servers. Anyone running servers or appliances built on the MegaRAC SP-X BMC is affected, including NetApp FAS (H300S, H500S, H700S), HCI (H410S, H410C), and StorageGRID (SG6160, SGF6112, SG110, SG1100) appliances that embed this BMC. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-25, and EPSS assigns a 60.7% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known. Do: Apply the patched MegaRAC SP-X firmware distributed by your server OEM, or the updated BMC firmware referenced in NetApp's security advisory for the affected FAS, HCI, and StorageGRID appliance models (fixed version numbers were not included in this data set). Until patched, restrict access to BMC management interfaces (including Redfish/IPMI) by isolating them from the internet and untrusted network segments, and scan for externally exposed BMC ports. As the flaw is on CISA's KEV catalog (added 2025-06-25), federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. | 10.0 | 61% | KEV |
| massHundreds of thousands to millions of server BMCs (AMI's MegaRAC SP-X is embedded in server lines from many OEMs, and public internet-wide scans have repeatedly… |
Full article325 words · extracted from arstechnica.com · click to collapse
On Wednesday, CISA added CVE-2024-54085 to its list of vulnerabilities known to be exploited in the wild. The notice provided no further details.
In an email on Thursday, Eclypsium researchers said the scope of the exploits has the potential to be broad:
- Attackers could chain multiple BMC exploits to implant malicious code directly into the BMC’s firmware, making their presence extremely difficult to detect and allowing them to survive OS reinstalls or even disk replacements.
- By operating below the OS, attackers can evade endpoint protection, logging, and most traditional security tools.
- With BMC access, attackers can remotely power on or off, reboot, or reimage the server, regardless of the primary operating system’s state.
- Attackers can scrape credentials stored on the system, including those used for remote management, and use the BMC as a launchpad to move laterally within the network
- BMCs often have access to system memory and network interfaces, enabling attackers to sniff sensitive data or exfiltrate information without detection
- Attackers with BMC access can intentionally corrupt firmware, rendering servers unbootable and causing significant operational disruption
With no publicly known details of the ongoing attacks, it’s unclear which groups may be behind them. Eclypsium said the most likely culprits would be espionage groups working on behalf of the Chinese government. All five of the specific APT groups Eclypsium named have a history of exploiting firmware vulnerabilities or gaining persistent access to high-value targets.
Eclypsium said the line of vulnerable AMI MegaRAC devices uses an interface known as Redfish. Server makers known to use these products include AMD, Ampere Computing, ASRock, ARM, Fujitsu, Gigabyte, Huawei, Nvidia, and Qualcomm. Some, but not all, of these vendors have released patches for their wares.
Given the damage possible from exploitation of this vulnerability, admins should examine all BMCs in their fleets to ensure they aren’t vulnerable. With products from so many different server makers affected, admins should consult with their manufacturer when unsure if their networks are exposed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/