ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Critical AMI BMC Vulnerability Enables Remote Server Takeover and Bricking

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26872
AMI Megarac Password reset interception via API

AMI Megarac Password reset interception via API

NVD description · AI analysis pending
8.8<1%
  • ami megarac sp-x
CVE-2022-40242
+2 in the same advisory: …40259 …2827
MegaRAC Default Credentials Vulnerability

MegaRAC Default Credentials Vulnerability

NVD description · AI analysis pending
9.8
group max
<1%
  • ami megarac sp-x
CVE-2022-40258
AMI Megarac Weak password hashes for Redfish & API

AMI Megarac Weak password hashes for Redfish & API

NVD description · AI analysis pending
5.3<1%
  • ami megarac spx-12
  • ami megarac spx-13
CVE-2023-34330
+1 in the same advisory: …34329
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface.

AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

NVD description · AI analysis pending
8.8
group max
<1%
  • ami megarac sp-x
CVE-2024-54085
Remote Authentication Bypass by Spoofing in AMI MegaRAC SP-X BMC

CVE-2024-54085 is an authentication bypass by spoofing (CWE-290) in the AMI MegaRac SP-X baseboard management controller (BMC), allowing a remote attacker to impersonate an authorized client through the Redfish Host Interface without valid credentials. The flaw is network-exploitable with low attack complexity, no required privileges, and no user interaction, which is why it carries a maximum CVSS 4.0 score of 10.0. A successful attacker gains full BMC-level control of the host, with high impact to confidentiality, integrity, and availability; published coverage describes remote server takeover, including the ability to run attacker code and even brick servers. Anyone running servers or appliances built on the MegaRAC SP-X BMC is affected, including NetApp FAS (H300S, H500S, H700S), HCI (H410S, H410C), and StorageGRID (SG6160, SGF6112, SG110, SG1100) appliances that embed this BMC. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-25, and EPSS assigns a 60.7% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known.

Do: Apply the patched MegaRAC SP-X firmware distributed by your server OEM, or the updated BMC firmware referenced in NetApp's security advisory for the affected FAS, HCI, and StorageGRID appliance models (fixed version numbers were not included in this data set). Until patched, restrict access to BMC management interfaces (including Redfish/IPMI) by isolating them from the internet and untrusted network segments, and scan for externally exposed BMC ports. As the flaw is on CISA's KEV catalog (added 2025-06-25), federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.

10.061% KEV
  • AMI MegaRAC SP-X (BMC firmware)
  • NetApp H300S firmware (FAS appliance with embedded AMI MegaRAC BMC)
  • NetApp H500S firmware (FAS appliance with embedded AMI MegaRAC BMC)
  • +7 more
massHundreds of thousands to millions of server BMCs (AMI's MegaRAC SP-X is embedded in server lines from many OEMs, and public internet-wide scans have repeatedly…
Full article420 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 18, 2025Vulnerability / Firmware Security

A critical security vulnerability has been disclosed in AMI's MegaRAC Baseboard Management Controller (BMC) software that could allow an attacker to bypass authentication and carry out post-exploitation actions.

The vulnerability, tracked as CVE-2024-54085, carries a CVSS v4 score of 10.0, indicating maximum severity.

"A local or remote attacker can exploit the vulnerability by accessing the remote management interfaces (Redfish) or the internal host to the BMC interface (Redfish)," firmware security company Eclypsium said in a report shared with The Hacker News.

"Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop."

The vulnerability can further be weaponized to stage disruptive attacks, causing susceptible devices to continually reboot by sending malicious commands. This could then pave the way for indefinite downtime until the devices are re-provisioned.

CVE-2024-54085 is the latest in a long list of security shortcomings that have been uncovered in AMI MegaRAC BMCs since December 2022. They have been collectively tracked as BMC&C -

Eclypsium noted that CVE-2024-54085 is similar to CVE-2023-34329 in that it allows for an authentication bypass with a similar impact. The vulnerability has been confirmed to affect the below devices -

  • HPE Cray XD670
  • Asus RS720A-E11-RS24U
  • ASRockRack

AMI has released patches to address the flaw as of March 11, 2025. While there is no evidence that the issue has been exploited in the wild, it's essential that downstream users update their systems once OEM vendors incorporate these fixes and release them to their customers.

HPE and Lenovo have already released security updates for their products that integrate AMI’s fix for CVE-2024-54085.

"Note that patching these vulnerabilities is a non-trivial exercise, requiring device downtime," Eclypsium said. "The vulnerability only affects AMI's BMC software stack. However, since AMI is at the top of the BIOS supply chain, the downstream impact affects over a dozen manufacturers."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/new-critical-ami-bmc-vulnerability.html