A new critical severity vulnerability found in American Megatrends International's MegaRAC Baseboard Management Controller (BMC) software can let attackers hijack and potentially brick vulnerable servers. MegaRAC BMC provides "lights-out" and "out-of-band" remote system management capabilities that help admins troubleshoot servers as if they were physically in front of the devices. The firmware is used by over a dozen server vendors that provide equipment to many cloud service and data center providers, including HPE, Asus, ASRock, and others. Remote unauthenticated attackers can exploit this maximum severity security flaw (tracked as CVE-2024-54085) in low-complexity attacks that don't require user interaction. "A local or remote attacker can exploit the vulnerability by accessing the remote management interfaces (Redfish) or the internal host to the BMC interface (Redfish)," Eclypsium explained in a Tuesday report. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop." Eclypsium security researchers discovered the CVE-2024-54085 auth bypass while analyzing patches issued by AMI for CVE-2023-34329, another authentication bypass the cybersecurity company disclosed in July 2023. While Eclypsium conf...
Critical AMI MegaRAC bug can let attackers hijack, brick servers
BleepingComputer
·Sergiu Gatlan
·Published Mar 18, 2025
·Updated
Affected Software
5 affected components
American Megatrends International MegaRAC Baseboard Management Controller (BMC)
HPE Cray XD670
ASUS RS720A-E11-RS24U
ASRockRack
American Megatrends International MegaRAC BMC
Frequently Asked Questions
1
What is the main subject of this article?
The article discusses a critical vulnerability in the MegaRAC Baseboard Management Controller (BMC) software that allows attackers to hijack and potentially brick servers.
2
What are the potential consequences of the vulnerability?
The vulnerability can lead to unauthorized access to servers and the possibility of permanently disabling them.
3
Which software or products are primarily affected by this security flaw?
The affected products include American Megatrends International MegaRAC BMC, HPE Cray XD670, and Asus RS720A-E11-RS24U.
4
Who discovered this critical security vulnerability?
The article does not specify the researchers or organization that discovered the vulnerability.
5
What action should users take regarding the vulnerability?
Users should monitor for patches or updates from the manufacturers to secure their systems against this flaw.