← Back to browse · API

CVE-2024-54085

Severity
CRITICAL
CVSS
10.0
EPSS
0.59193
Risk score
85.72
CISA KEV
Yes
PoC
No
Published
2025-06-25
Modified
2025-06-25
First seen
2026-08-07
Aliases
EUVD-2024-54252, GHSA-VCGC-H73Q-2M2P
Products
AMI:MegaRAC SPx, AMI:MegaRAC-SPx 12.0 <12.7, AMI:MegaRAC-SPx 13.0 <13.5
Sources
euvd EUVD-2024-54252
cisa.gov CVE-2024-54085

Description

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

References