CVE-2024-54085
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
11/03/2025
Last modified:
05/11/2025
Description
AMI’s SPx contains<br />
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation<br />
of this vulnerability may lead to a loss of confidentiality, integrity, and/or<br />
availability.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | 12 (including) | 12.7 (excluding) |
| cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | 13 (including) | 13.5 (excluding) |
| cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:sg6160_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:sg6160:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:sgf6112_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf
- https://arstechnica.com/security/2025/06/active-exploitation-of-ami-management-tool-imperils-thousands-of-servers/
- https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/
- https://security.netapp.com/advisory/ntap-20250328-0003/
- https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/
- https://www.networkworld.com/article/4013368/ami-megarac-authentication-bypass-flaw-is-being-exploitated-cisa-warns.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-54085
- https://security.netapp.com/advisory/ntap-20250328-0003/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-54085



