logo

A Vulnerability in AMI MegaRAC Software Could Allow for Remote Code Execution

ID: 4a350d77-19f2-5c20-8b0c-69463922bd86

STIX ID: report--4a350d77-19f2-5c20-8b0c-69463922bd86

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-03-20

Date Updated: 2026-04-27

...
...

**Executive summary:** A vulnerability in AMI MegaRAC BMC's Redfish host interface can be exploited to bypass authentication and achieve remote code execution, potentially allowing full server control, malware or ransomware deployment, firmware tampering, and permanent hardware damage; the issue is mapped to ATT&CK T1190 (Exploit Public‑Facing Application) and TA0001 (Initial Access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.