• News/
  • https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bug-can-let-attackers-hijack-brick-servers/

Critical AMI MegaRAC bug can let attackers hijack, brick servers

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 18, 2025
·
Updated

​A new critical severity vulnerability found in American Megatrends International's MegaRAC Baseboard Management Controller (BMC) software can let attackers hijack and potentially brick vulnerable servers. MegaRAC BMC provides "lights-out" and "out-of-band" remote system management capabilities that help admins troubleshoot servers as if they were physically in front of the devices. The firmware is used by over a dozen server vendors that provide equipment to many cloud service and data center providers, including HPE, Asus, ASRock, and others. Remote unauthenticated attackers can exploit this maximum severity security flaw (tracked as CVE-2024-54085) in low-complexity attacks that don't require user interaction. "A local or remote attacker can exploit the vulnerability by accessing the remote management interfaces (Redfish) or the internal host to the BMC interface (Redfish)," Eclypsium explained in a Tuesday report. "Exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop." Eclypsium security researchers discovered the CVE-2024-54085 auth bypass while analyzing patches issued by AMI for CVE-2023-34329, another authentication bypass the cybersecurity company disclosed in July 2023. While Eclypsium conf...

Read full article

Affected Software

5 affected components
American Megatrends International MegaRAC Baseboard Management Controller (BMC)
HPE Cray XD670
ASUS RS720A-E11-RS24U
ASRockRack
American Megatrends International MegaRAC BMC

Frequently Asked Questions

1

What is the main subject of this article?

The article discusses a critical vulnerability in the MegaRAC Baseboard Management Controller (BMC) software that allows attackers to hijack and potentially brick servers.

2

What are the potential consequences of the vulnerability?

The vulnerability can lead to unauthorized access to servers and the possibility of permanently disabling them.

3

Which software or products are primarily affected by this security flaw?

The affected products include American Megatrends International MegaRAC BMC, HPE Cray XD670, and Asus RS720A-E11-RS24U.

4

Who discovered this critical security vulnerability?

The article does not specify the researchers or organization that discovered the vulnerability.

5

What action should users take regarding the vulnerability?

Users should monitor for patches or updates from the manufacturers to secure their systems against this flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203