CVE-2024-54085 is a critical authentication bypass vulnerability in AMI’s SPx BMC, specifically affecting the Redfish Host Interface, with confirmed impact on AMI and NetApp products. This vulnerability, rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), allows unauthenticated remote attackers to gain full control, leading to a complete loss of confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog and CISA warnings, despite no public exploit code being available in common repositories like Metasploit or ExploitDB. The vulnerability has garnered significant community discussion and media coverage, indicating high awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12, < 12.7CPE matchmatch criteria | cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | ||
>= 13, < 13.5CPE matchmatch criteria | cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.