• News/
  • bleepingcomputer-20250626083805

CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks

BleepingComputer
·
Published Jun 26, 2025
·
Updated

CISA has confirmed that a maximum severity vulnerability in AMI's MegaRAC Baseboard Management Controller (BMC) software is now actively exploited in attacks. The MegaRAC BMC firmware provides remote system management capabilities for troubleshooting servers without being physically present, and it's used by several vendors (including HPE, Asus, and ASRock) that supply equipment to cloud service providers and data centers. This authentication bypass security flaw (tracked as CVE-2024-54085) can be exploited by remote unauthenticated attackers in low-complexity attacks that don't require user interaction to hijack and potentially brick unpatched servers. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop," explained supply chain security company Eclypsium who discovered the vulnerability. Eclypsium researchers discovered CVE-2024-54085 while analyzing patches issued by AMI for another authentication bypass bug (CVE-2023-34329) disclosed in July 2023. In March, when the AMI released security updates to fix CVE-2024-54085, Eclypsium found more than 1,000 servers online that were potentially exposed to attacks and said that creating an exploit is "not challenging," seeing that MegaRAC BMC firmware bin...

Read full article

Affected Software

2 affected components
AMI MegaRAC Baseboard Management Controller (BMC) software
AMI MegaRAC Baseboard Management Controller (BMC) firmware
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in AMI's MegaRAC Baseboard Management Controller software that is being actively exploited in attacks.

2

What security implications are discussed?

The vulnerability allows attackers to hijack servers using the MegaRAC BMC software, posing significant risks to server security.

3

What products or software are affected?

The affected product is AMI's MegaRAC Baseboard Management Controller (BMC) firmware.

4

When was this vulnerability first listed in the Known Exploited Vulnerabilities database?

The vulnerability was listed in the Known Exploited Vulnerabilities database on June 12, 2026.

5

Which organization has confirmed the exploitation of this vulnerability?

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the exploitation of the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203