AMI.MegaRAC.SPx.CVE-2024-54085.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass Vulnerability in AMI MegaRAC SPx.
The vulnerability is due to improper handling of authentication for functions of the software. A remote, unauthenticated attacker can exploit the vulnerability by sending malicious requests to the vulnerable system. Successful exploitation could allow an attacker to log in as an authenticated user and perform actions that can further compromise the system.

affected-products-logoAffected Products

AMI MegaRAC SPx 12.x prior to 12.7+
AMI MegaRAC SPx 13.x prior to 13.5

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-08-27 34.072
Modified
Sig Added
2025-06-09 33.021
Modified
Default_action:pass:drop
2025-05-28 33.015
New