Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New critical AMI BMC vulnerabilities allow takeover and bricking of remote servers
Celebrities

New critical AMI BMC vulnerabilities allow takeover and bricking of remote servers

By March 18, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 18, 2025Ravi LakshmananVulnerability/Firmware Security

AMI BMC Vulnerability

AMI’s Megarac Baseboard Management Controller (BMC) software reveals a critical security vulnerability that allows attackers to bypass authentication and take post-exposure actions.

The vulnerability tracked as CVE-2024-54085 is equipped with a CVSS V4 score of 10.0, indicating maximum severity.

“Local or remote attackers can take advantage of the vulnerability by accessing an internal host on a remote management interface (Redfish) or a BMC interface (Redfish),” firmware security company Eclypsium said in a report shared with Hacker News.

“By exploiting this vulnerability, an attacker can remotely control a compromised server, allowing malware, ransomware, firmware tampering, bridging motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (overvoltage/bricking), and victim reboot loops.

Additionally, vulnerabilities can be weaponized to phase out destructive attacks, and by sending malicious commands, sensitive devices will be rebooted continuously. This could pave the way for indefinite downtime until the device is reconfigured.

Cybersecurity

CVE-2024-54085 is the latest list of long list of security drawbacks discovered in Ami Megarac BMC since December 2022.

Eclypsium pointed out that CVE-2024-54085 is similar to CVE-2023-34329. The vulnerability has been found to affect the following devices:

HPE Cray XD670 ASUS RS720A-E11-RS24U ASROCKRACK

AMI has released a patch to address the defects as of March 11, 2025. There is no evidence that the issue has been exploited in the wild, but it is essential that downstream users update the system once OEM vendors incorporate these fixes and release them to customers.

“Please note that patching these vulnerabilities is a non-trivial exercise and requires downtime on the device,” Eclypsium said. “The vulnerability affects AMI’s BMC software stack only. However, since AMI is at the top of the BIOS supply chain, the downstream impact will affect 12 manufacturers.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGoogle acquires cloud security startup Wiz for $32 billion. This is the biggest deal ever
Next Article Vote for the speaker you want to watch in the session: ai

Related Posts

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Zendaya & Tom Holland’s ‘Spider-Man’ Press Tour Couple Style

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Bettina Anderson reveals the designer of her wedding dress

Trending Posts

Vote for Sombre, Phoebe Bridgers and more

June 26, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.