Urgent Alert: Critical Vulnerability Allows Attackers to Seize Control and Destroy Servers Remotely


# Critical Vulnerability in MegaRAC BMC Software Threatens Server Security

A newly discovered critical vulnerability in American Megatrends International’s MegaRAC Baseboard Management Controller (BMC) software poses significant risks to server infrastructure worldwide. Tracked as CVE-2024-54085, this maximum severity flaw allows unauthenticated attackers to remotely hijack and potentially brick vulnerable servers without requiring user interaction.

## Widespread Impact

MegaRAC BMC software provides essential remote management capabilities for servers, allowing administrators to troubleshoot systems remotely. The vulnerability affects equipment from numerous major vendors including HPE, Asus, and ASRock, with potentially more affected devices yet to be identified. Security researchers at Eclypsium have already detected over 1,000 servers exposed to potential internet attacks through Shodan searches.

## Severe Consequences

Successful exploitation enables attackers to:
– Remotely control compromised servers
– Deploy malware or ransomware
– Tamper with firmware
– Brick motherboard components
– Potentially cause physical damage through over-voltage
– Create indefinite reboot loops that victims cannot stop

## Part of a Larger Vulnerability Pattern

This flaw was discovered while analyzing patches for a previous authentication bypass vulnerability (CVE-2023-34329). Eclypsium researchers have previously identified several other MegaRAC vulnerabilities collectively tracked as BMC&C, including code injection flaws and weak password hash implementations that could be chained together in sophisticated attacks.

## Mitigation Recommendations

While no exploits have been detected in the wild yet, creating one would not be challenging as the firmware binaries are unencrypted. Network defenders should:
– Apply patches released by AMI, Lenovo, and HPE immediately
– Avoid exposing AMI MegaRAC instances online
– Monitor server logs for suspicious activity

Patching these vulnerabilities requires device downtime and is considered a non-trivial exercise, but is essential given the critical nature of the vulnerability and its potential impact on server infrastructure.

Share This Article