CISA warns of ongoing exploitation of critical vulnerabilities in AMI BMC and FortiOS, affecting various organizations and devices. These vulnerabilities pose significant risks, including remote control, data theft, and firmware modification. #AMI BMC #FortiOS
Keypoints
- CISA has identified active exploitation of a critical AMI BMC vulnerability impacting multiple OEM products.
- The CVE-2024-54085 flaw affects the Redfish management interface, enabling attackers to take control of affected systems.
- Over half a decade old FortiOS bug involving hardcoded cryptographic keys was also added to the KEV catalog.
- Federal agencies are required to patch affected products by July 17 under Binding Operational Directive 22-01.
- Discontinued D-Link routers with CVE-2024-0769 and other vulnerabilities have been exploited in the wild for over a year.
Read More: https://www.securityweek.com/cisa-warns-ami-bmc-vulnerability-exploited-in-the-wild/