CVE-2024-54085 is a critical authentication bypass vulnerability in AMI MegaRAC SPx Baseboard Management Controller firmware affecting the Redfish Host Interface. The flaw allows a remote attacker to spoof access through the Redfish Host Interface and bypass normal authentication controls on the BMC. Successful exploitation can grant unauthorized access to the management plane of affected systems, enabling takeover of the BMC and abuse of its privileged out-of-band management capabilities. Because the issue resides in BMC firmware, compromise can occur below the operating system and can support stealthy, persistent control over the underlying server platform.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2024-54085, a critical authentication bypass vulnerability in AMI MegaRAC BMC and related server products. The exploit is implemented in a single Python script (CVE_2024-54085.py), which takes a target BMC Redfish API URL as input. It attempts to create a new administrative user account by sending POST requests to the /redfish/v1/AccountService/Accounts endpoint, using specially crafted X-Server-Addr headers with various internal IP addresses to bypass authentication. If successful, the script outputs the credentials for the newly created admin account, granting the attacker full control over the BMC. The README.md provides detailed information about affected products, the nature of the vulnerability, and the potential impact, including full remote control, firmware modification, and lateral movement within management networks. The exploit is operational and demonstrates a real-world attack scenario against vulnerable BMCs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical AMI MegaRAC BMC vulnerability that allows authentication bypass and can enable remote server takeover and potentially device bricking.
An authentication bypass vulnerability (by spoofing) affecting AMI MegaRAC, added to CISA KEV due to active exploitation.
A critical (CVSS 10.0) authentication bypass in AMI MegaRAC firmware related to the Redfish Host Interface, enabling remote attackers to bypass authentication.
A critical authentication bypass vulnerability in the Redfish Host Interface of AMI MegaRAC SPx BMC, allowing remote attackers to take control and potentially deploy malware or tamper with firmware.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.