logo

Critical AMI MegaRAC bug can let attackers hijack, brick servers

ID: 556d40e2-8b96-5b23-a626-befb9d35346b

STIX ID: report--556d40e2-8b96-5b23-a626-befb9d35346b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Executive summary: A critical authentication-bypass vulnerability (CVE-2024-54085) was discovered in American Megatrends' MegaRAC BMC firmware, enabling unauthenticated remote control that can lead to malware deployment, firmware tampering, or bricking of servers; Eclypsium found ~1,000 potentially exposed instances, affected major OEMs (HPE, Asus, ASRock, Lenovo, etc.), and recommends immediate patching and removal of internet exposure—no active exploitation observed but exploits are considered easy to develop.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.