EXPOSURES › CVE-2024-54085
CVE-2024-54085
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatchedrce
AMI MegaRAC SPx spoofing flaw exploited
AMI's MegaRAC SPx suffered an unpatched authentication bypass through spoofing, allowing attackers to compromise system integrity and confidentiality.
Shame score — Critical unpatched vulnerability enabling remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.