CVE-2024-54085
AMI · Published March 11, 2025
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Affected Products
- Megarac SP X < 12.7
- Megarac SP X < 13.5
- H300s Firmware
- H500s Firmware
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H