• News/
  • https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/

CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 26, 2025
·
Updated

CISA has confirmed that a maximum severity vulnerability in AMI's MegaRAC Baseboard Management Controller (BMC) software is now actively exploited in attacks. The MegaRAC BMC firmware provides remote system management capabilities for troubleshooting servers without being physically present, and it's used by several vendors (including HPE, Asus, and ASRock) that supply equipment to cloud service providers and data centers. This authentication bypass security flaw (tracked as CVE-2024-54085) can be exploited by remote unauthenticated attackers in low-complexity attacks that don't require user interaction to hijack and potentially brick unpatched servers. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop," explained supply chain security company Eclypsium who discovered the vulnerability. Eclypsium researchers discovered CVE-2024-54085 while analyzing patches issued by AMI for another authentication bypass bug (CVE-2023-34329) disclosed in July 2023. In March, when the AMI released security updates to fix CVE-2024-54085, Eclypsium found more than 1,000 servers online that were potentially exposed to attacks and said that creating an exploit is "not challenging," seeing that MegaRAC BMC firmware bin...

Read full article

Affected Software

1 affected component
AMI MegaRAC Baseboard Management Controller
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a severe vulnerability in AMI's MegaRAC BMC software that is currently being actively exploited by attackers.

2

What security implications are discussed?

The article highlights that the vulnerability allows hackers to remotely hijack and potentially brick servers.

3

What products or software are affected by the vulnerability?

Affected products include AMI MegaRAC BMC, HPE MegaRAC BMC, Asus MegaRAC BMC, and ASRock MegaRAC BMC.

4

Who confirmed the exploitation of the vulnerability?

The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the vulnerability is being actively exploited.

5

What should organizations do in response to the vulnerability?

Organizations should prioritize updating or patching impacted MegaRAC BMC software to mitigate the risk of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203