CVE-2024-54085: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Other sources
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Ami Megarac SPx-13from your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54085?
The vulnerability CVE-2024-54085 is considered critical due to its potential to allow remote authentication bypass.
How do I fix CVE-2024-54085?
To remediate CVE-2024-54085, it is recommended to apply the latest security patches provided by AMI for the SPx product.
What are the risks associated with CVE-2024-54085?
Exploitation of CVE-2024-54085 may result in loss of confidentiality, integrity, and availability of the system.
Who is affected by CVE-2024-54085?
CVE-2024-54085 affects all users of the AMI SPx BMC that utilize the Redfish Host Interface.
Can CVE-2024-54085 be exploited without physical access?
Yes, CVE-2024-54085 can be exploited remotely, allowing attackers to bypass authentication without physical access.