CVE-2024-54085

CRITICAL KEV

AMI's SPx - Auth Bypass

Title source: llm

Description

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

Exploits (2)

nomisec WORKING POC 2 stars
by Mr-Zapi · remote
https://github.com/Mr-Zapi/CVE-2024-54085
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2024/CVE-2024-54085

Scores

CVSS v3 9.8
EPSS 0.0824
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-06-25
VulnCheck KEV 2025-06-25
ENISA EUVD EUVD-2024-54252

Classification

CWE
CWE-290
Status published

Affected Products (10)

ami/megarac_sp-x < 12.7
netapp/h300s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/h410s_firmware
netapp/h410c_firmware
netapp/sg6160_firmware
netapp/sgf6112_firmware
netapp/sg110_firmware
netapp/sg1100_firmware

Timeline

Published Mar 11, 2025
KEV Added Jun 25, 2025
Tracked Since Feb 18, 2026