CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
ID: d1ca7ecb-16a1-5f10-8fe7-e93205db6688
STIX ID: report--d1ca7ecb-16a1-5f10-8fe7-e93205db6688
Feed Name: Bleeping Computer
Threat Score
CISA confirmed active exploitation of a critical authentication-bypass vulnerability (CVE-2024-54085) in AMI MegaRAC BMC firmware that can let unauthenticated remote attackers fully control or brick servers; Eclypsium discovered the issue and found many exposed instances, AMI released patches, and CISA added the flaw to its Known Exploited Vulnerabilities catalog, prompting urgent patching directives for federal agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
