UNCOS

Actively exploited vulnerability gives extraordinary control over server fleets

Actively exploited vulnerability gives extraordinary control over server fleets

image via Ars Technica

June 26, 2025, 10:52 PM

  • Hackers are exploiting a maximum-severity vulnerability in AMI MegaRAC firmware, which could grant them complete control over thousands of servers.
  • The vulnerability, CVE-2024-54085, allows for authentication bypasses via a simple web request.
  • Affected server manufacturers include AMD, ARM, Fujitsu, Gigabyte, Supermicro, and Qualcomm.
  • Administrators should check BMCs and consult manufacturers to ensure their networks are not exposed.

A critical vulnerability (CVE-2024-54085) in AMI MegaRAC firmware, used in servers from various manufacturers, is being actively exploited. This flaw allows attackers to bypass authentication and gain complete control over servers, potentially compromising mission-critical data. The vulnerability, discovered by Eclypsium, affects a wide range of server brands, including AMD, ARM, Fujitsu, and Supermicro, and exploits the Redfish interface. CISA has added the vulnerability to its list of actively exploited flaws, urging administrators to check their systems and apply patches to prevent potential attacks.

Read original article

Entities Mentioned

Eclypsium

Topics Covered

Biz & ITSecurityAMI MegaRACbaseboard management controllersbmcsexploits

Comments (0)

No comments yet.