ASUS Releases Critical Fix for Severe AMI Vulnerability That Can Permanently Destroy Servers


# ASUS Releases Critical Security Updates for Server Vulnerability

ASUS has issued urgent security patches for CVE-2024-54085, a critical vulnerability affecting American Megatrends International’s MegaRAC Baseboard Management Controller (BMC) software. This severe flaw, which could allow attackers to remotely hijack or permanently damage servers, impacts multiple hardware vendors including HPE, ASUS, and ASRock.

## The Vulnerability

The remotely exploitable vulnerability enables attackers to access management interfaces and potentially:
– Deploy malware or ransomware
– Tamper with firmware
– Cause physical damage through over-volting
– Create uninterruptible reboot loops
– Permanently disable server components

“A local or remote attacker can exploit the vulnerability by accessing the remote management interfaces (Redfish) or the internal host to the BMC interface,” security firm Eclypsium reported.

## Affected Models and Updates

ASUS has released fixes for four affected motherboard models:

– PRO WS W790E-SAGE SE – Update to version 1.1.57
– PRO WS W680M-ACE SE – Update to version 1.1.21
– PRO WS WRX90E-SAGE SE – Update to version 2.1.28
– Pro WS WRX80E-SAGE SE WIFI – Update to version 1.34.0

## Urgent Update Recommended

Due to the severity of this vulnerability, immediate firmware updates are strongly recommended. Users can apply updates through the web interface by navigating to Maintenance > Firmware Update, selecting the downloaded .ima file, and clicking ‘Start Firmware Update.’ Enabling the ‘Full Flash’ option is also advised.

For detailed update instructions and troubleshooting guidance, users should consult the ASUS FAQ documentation.

Share This Article