← Vulnerability feed

Vulnerability record · CVE-2024-54085 · published 11 March 2025

CVE-2024-54085: AMI MegaRAC SPx BMC authentication bypass via Redfish Host Interface

Ami · Megarac Sp X

AMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authentication bypass by spoofing). Because the BMC controls server power, firmware and out-of-band management, a bypass there undermines the integrity of the whole host, and the record lists NetApp hardware firmware among affected products.

10.0 CVSS 4.0 Critical CISA KEV since 25 Jun 2025 EPSS 61% · top 0.9% CWE-290 · Authentication bypass by spoofing
10.0CVSS 4.0 base score
61%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score of 10.0, unauthenticated remote authentication bypass, active exploitation per KEV, and very high EPSS probability make this an urgent patch-first issue.

What it is

AMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authentication bypass by spoofing). Because the BMC controls server power, firmware and out-of-band management, a bypass there undermines the integrity of the whole host, and the record lists NetApp hardware firmware among affected products.

Impact

An unauthenticated attacker gains full control of the BMC, with high confidentiality, integrity and availability impact on both the vulnerable system and subsequent systems, meaning potential data theft, firmware tampering, or bricking of the server.

Attack surface

Reachable over the network via the Redfish Host Interface with no privileges and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The description does not specify which interface exposure or configuration is required beyond the Redfish Host Interface.

Exploitation

Listed in CISA KEV with a 2025-06-25 addition and 2025-07-16 remediation due date, and multiple references describe active exploitation; EPSS 30-day probability is 0.60747 (99.1st percentile). No ransomware campaign use is documented in this record.

What to do

  • Apply the vendor mitigations in AMI security advisory AMI-SA-2025003 and the NetApp advisory ntap-20250328-0003, or discontinue use of affected products if no fix is available, per CISA's required action.
  • Isolate BMC/Redfish management interfaces from untrusted networks and restrict them to a dedicated, access-controlled management VLAN.
  • Disable or block the Redfish Host Interface where it is not operationally required.
  • Monitor CISA KEV guidance and BOD 22-01 requirements for cloud-connected instances of affected products.
  • Inventory all AMI MegaRAC SPx and listed NetApp firmware deployments to confirm which units remain unpatched.

Detection

  • Review BMC and Redfish authentication logs for successful sessions that lack a preceding credential exchange or that originate from unexpected source addresses.
  • Alert on anomalous BMC activity such as firmware updates, power resets, or user/account changes outside maintenance windows.
  • Monitor network traffic to BMC management ports for Redfish Host Interface access from non-management segments.
  • Correlate BMC log gaps or restarts with host-side events that could indicate tampering or bricking attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-54085 to the Known Exploited Vulnerabilities catalog on 25 June 2025 as "AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 July 2025.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-54085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2022-0185Linux Kernel Filesystem Context Heap Buffer OverflowThe legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a…KEVEPSS 25%analysed7.8CVE-2024-1086Linux kernel nf_tables use-after-free allows local privilege escalationThe Linux kernel's netfilter nf_tables component has a use-after-free in nft_verdict_init(), where positive drop errors are accepted and nf_hook_slow…KEVEPSS 28%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2023-0386Linux kernel OverlayFS setuid copy privilege escalationA uid mapping bug in the Linux kernel OverlayFS subsystem lets a local user copy a file with capabilities from a nosuid mount into another mount, byp…KEVEPSS 7.9%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed7.8CVE-2021-22555Linux kernel netfilter x_tables heap out-of-bounds writeA heap out-of-bounds write exists in the Linux kernel netfilter x_tables code (net/netfilter/x_tables.c), present since v2.6.19-rc1. A local attacker…KEVEPSS 79%analysed

Source: NIST National Vulnerability Database (record CVE-2024-54085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.