← Back to CVE List
Vulnerability Intelligence Report
Redfish Authentication Bypass

CVE-2024-54085

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
EPSS Probability:61.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-290 ↗CWE-290 Authentication Bypass by Spoofing

Affected Products & Versions

Vendor Product Affected Versions
AMI MegaRAC-SPx 12.0 < 12.7 (affected), 13.0 < 13.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
61.202%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAMI · Vendor · USA
Reserved2024-11-28T05:10:52
Published2025-03-11T14:00:58
Patch Date2025-03-11
Last Updated2026-02-26T19:09:41

LINK COPIED TO CLIPBOARD