CISA Known Exploited Vulnerability

CVE-2024-54085

AMI · MegaRAC SPx

AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

Date added
BOD 22-01 due date
CWE CWE-290
Ransomware Unknown

CISA description

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.