A critical vulnerability (CVE-2024-54085) in AMI’s MegaRAC BMC firmware is actively exploited, leading to severe consequences such as remote server control and potential hardware damage. Organizations using affected systems are urged to patch promptly to prevent ongoing attacks, with federal agencies mandated to do so by CISA. #MegaRAC #CVE2024-54085
Keypoints
- The vulnerability affects AMI’s MegaRAC BMC firmware, used in various servers and by multiple vendors.
- Exploitation allows attackers to hijack servers, deploy malware, and physically damage hardware.
- Over 1,000 servers were found exposed to this security flaw before patches were released.
- CISA has confirmed active exploitation and added the vulnerability to the Known Exploited Vulnerabilities list.
- Federal agencies are required to patch their servers by July 16 to prevent compromise.