CISA has confirmed that a maximum severity vulnerability in AMI's MegaRAC Baseboard Management Controller (BMC) software is now actively exploited in attacks. The MegaRAC BMC firmware provides remote system management capabilities for troubleshooting servers without being physically present, and it's used by several vendors (including HPE, Asus, and ASRock) that supply equipment to cloud service providers and data centers. This authentication bypass security flaw (tracked as CVE-2024-54085) can be exploited by remote unauthenticated attackers in low-complexity attacks that don't require user interaction to hijack and potentially brick unpatched servers. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop," explained supply chain security company Eclypsium who discovered the vulnerability. Eclypsium researchers discovered CVE-2024-54085 while analyzing patches issued by AMI for another authentication bypass bug (CVE-2023-34329) disclosed in July 2023. In March, when the AMI released security updates to fix CVE-2024-54085, Eclypsium found more than 1,000 servers online that were potentially exposed to attacks and said that creating an exploit is "not challenging," seeing that MegaRAC BMC firmware bin...
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jun 26, 2025
·Updated
Affected Software
1 affected component
AMI MegaRAC Baseboard Management Controller
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a severe vulnerability in AMI's MegaRAC BMC software that is currently being actively exploited by attackers.
2
What security implications are discussed?
The article highlights that the vulnerability allows hackers to remotely hijack and potentially brick servers.
3
What products or software are affected by the vulnerability?
Affected products include AMI MegaRAC BMC, HPE MegaRAC BMC, Asus MegaRAC BMC, and ASRock MegaRAC BMC.
4
Who confirmed the exploitation of the vulnerability?
The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the vulnerability is being actively exploited.
5
What should organizations do in response to the vulnerability?
Organizations should prioritize updating or patching impacted MegaRAC BMC software to mitigate the risk of exploitation.