Critical AMI MegaRAC bug can let attackers hijack, brick servers
ID: 556d40e2-8b96-5b23-a626-befb9d35346b
STIX ID: report--556d40e2-8b96-5b23-a626-befb9d35346b
Feed Name: Bleeping Computer
Executive summary: A critical authentication-bypass vulnerability (CVE-2024-54085) was discovered in American Megatrends' MegaRAC BMC firmware, enabling unauthenticated remote control that can lead to malware deployment, firmware tampering, or bricking of servers; Eclypsium found ~1,000 potentially exposed instances, affected major OEMs (HPE, Asus, ASRock, Lenovo, etc.), and recommends immediate patching and removal of internet exposure—no active exploitation observed but exploits are considered easy to develop.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
