Junglewise Threat Intelligence

CVE-2024-54085: AMI MegaRAC SPx authentication bypass in Redfish Host Interface

CVE-2024-54085 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-06-25

Technologies: NetApp H700s Firmware, NetApp H410s Firmware, NetApp H300s Firmware, NetApp H500s Firmware, NetApp H410c Firmware. Vendors: NetApp.

Executive brief

AMI MegaRAC SPx is a management software used in Baseboard Management Controllers (BMCs) to allow administrators to remotely manage and monitor servers. A critical vulnerability allows unauthorized individuals to bypass security checks and gain full control over the server hardware. This could lead to data theft, permanent damage to the server (bricking), or complete service outages. This vulnerability is currently being exploited in the wild.

Technical details

An authentication bypass vulnerability (CWE-290) exists in the Redfish Host Interface of the AMI MegaRAC SPx Baseboard Management Controller (BMC) firmware. The flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms via spoofing. Successful exploitation grants the attacker full administrative access to the BMC, enabling them to modify firmware, access sensitive data, or render the physical server inoperable. The vulnerability is confirmed to be actively exploited in the wild and affects multiple hardware vendors utilizing AMI's management solution, including various NetApp storage and compute products. Patches are available in MegaRAC SPx versions 12.7 and 13.5.

Affected products

  • AMI MegaRAC SPx 12.x before 12.7, 13.x before 13.5
  • NetApp H300S Firmware
  • NetApp H410C Firmware
  • NetApp H410S Firmware
  • NetApp H500S Firmware
  • NetApp H700S Firmware
  • NetApp SG1100 Firmware
  • NetApp SG110 Firmware
  • NetApp SG6160 Firmware
  • NetApp SGF6112 Firmware

Timeline

  • 2025-06-25: advisory: Initial disclosure and CISA KEV addition
  • 2025-06-25: exploited: Confirmed active exploitation in the wild

Related threats