CISA has confirmed that a maximum severity vulnerability in AMI's MegaRAC Baseboard Management Controller (BMC) software is now actively exploited in attacks. The MegaRAC BMC firmware provides remote system management capabilities for troubleshooting servers without being physically present, and it's used by several vendors (including HPE, Asus, and ASRock) that supply equipment to cloud service providers and data centers. This authentication bypass security flaw (tracked as CVE-2024-54085) can be exploited by remote unauthenticated attackers in low-complexity attacks that don't require user interaction to hijack and potentially brick unpatched servers. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop," explained supply chain security company Eclypsium who discovered the vulnerability. Eclypsium researchers discovered CVE-2024-54085 while analyzing patches issued by AMI for another authentication bypass bug (CVE-2023-34329) disclosed in July 2023. In March, when the AMI released security updates to fix CVE-2024-54085, Eclypsium found more than 1,000 servers online that were potentially exposed to attacks and said that creating an exploit is "not challenging," seeing that MegaRAC BMC firmware bin...
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
BleepingComputer
·Published Jun 26, 2025
·Updated
Affected Software
2 affected components
AMI MegaRAC Baseboard Management Controller (BMC) software
AMI MegaRAC Baseboard Management Controller (BMC) firmware
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in AMI's MegaRAC Baseboard Management Controller software that is being actively exploited in attacks.
2
What security implications are discussed?
The vulnerability allows attackers to hijack servers using the MegaRAC BMC software, posing significant risks to server security.
3
What products or software are affected?
The affected product is AMI's MegaRAC Baseboard Management Controller (BMC) firmware.
4
When was this vulnerability first listed in the Known Exploited Vulnerabilities database?
The vulnerability was listed in the Known Exploited Vulnerabilities database on June 12, 2026.
5
Which organization has confirmed the exploitation of this vulnerability?
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the exploitation of the vulnerability.