A severe security vulnerability has been identified in AMI’s MegaRAC Baseboard Management Controller (BMC) software, designated as CVE-2024-54085 with a maximum CVSS v4 score of 10.0. This flaw enables attackers to bypass authentication mechanisms and execute unauthorized actions on affected systems.
According to firmware security firm Eclypsium, attackers can exploit this vulnerability by accessing remote management interfaces (Redfish) or the internal host-to-BMC interface. Once compromised, attackers can:
– Remotely control servers
– Deploy malware or ransomware
– Tamper with firmware
– Damage motherboard components
– Potentially cause physical hardware damage
– Create indefinite reboot loops that victims cannot interrupt
The vulnerability can be weaponized to cause continuous device reboots through malicious commands, potentially resulting in extended downtime until systems are re-provisioned.
## Part of a Larger Pattern
CVE-2024-54085 joins several other security flaws discovered in AMI MegaRAC BMCs since December 2022, collectively known as BMC&C:
– CVE-2022-40259: Arbitrary code execution via Redfish API
– CVE-2022-40242: Default credentials for UID = 0 shell via SSH
– CVE-2022-2827: User enumeration via API
– CVE-2022-26872: Password reset interception via API
– CVE-2022-40258: Weak password hashes for Redfish & API
– CVE-2023-34329: Authentication bypass via HTTP header spoofing
– CVE-2023-34330: Code injection via Dynamic Redfish Extension interface
Eclypsium notes that the current vulnerability resembles CVE-2023-34329, with similar authentication bypass capabilities and impact.
## Affected Devices
Confirmed affected devices include:
– HPE Cray XD670
– Asus RS720A-E11-RS24U
– ASRockRack
AMI released patches on March 11, 2025. While no in-the-wild exploitation has been detected, organizations should update their systems once OEM vendors incorporate these fixes.
Eclypsium warns that patching these vulnerabilities requires device downtime and is not trivial. Although the vulnerability only affects AMI’s BMC software stack, its position at the top of the BIOS supply chain means the downstream impact affects more than a dozen manufacturers.
