Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The new critical vulnerability AMI BMC allows remote server absorption and brick remedy
Global Security

The new critical vulnerability AMI BMC allows remote server absorption and brick remedy

AdminBy AdminMarch 18, 2025No Comments2 Mins Read
AMI BMC Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 18, 2025Red LakshmananVulnerability / firmware safety

AMI BMC vulnerability

The critical safety vulnerability has been disclosed in the MEGARAC AMI (BMC) software management software, which can allow the attacker to bypass authentication and carry out actions after operation.

Vulnerability tracked as Cve-2024-54085Carnate CVSS V4 10.0, indicating the maximum burden.

“Local or remote attacker can use vulnerability by accessing remote control (Redfish) or internal host BMC (Redfish)”, “Company Showare Security Company Eclypsium – Note In a report that shared with Hacker News.

“The operation of this vulnerability allows the attacker to remotely control the compromised server, remotely deploy malicious software, required software, firmware firming, bizarre components of the motherboard (BMC or potentially BIOS / UEFI), potential physical damage to the server Reboot that cannot stop. “

The vulnerability can be armed for devastating attacks, causing the sensitive devices to be constantly restarting, sending malicious teams. Then this can pave the way to uncertain downtime until the devices are re -.

Cybersecurity

The CVE-2024-54085-Apostle in the long list of security deficiencies, which have been found in BMC AMI Megaac since December 2022. They were collectively tracked as BMC & C-

Eclypsium noted that the CVE-2024-54085 is similar to the CVE-2023-34329 because it allows you to undergo authentication with similar impact. The vulnerability has been confirmed what affects the devices below – –

  • HPE Cray XD670
  • Asus RS720A-E11-RS24U
  • Asrockrack

AMI has Released patches To solve the lack of March 11, 2025. While there is no evidence that the problem has been used in the wild, it is important that users down the current update their systems when OEM providers include these fixes and release them to customers.

“Please note that the correction of these vulnerabilities is a non-trivial exercise that requires the downtime of the device,” Ellipseya said. “The vulnerability only affects the BMC AMI software stack. However, because Ami is at the top of the BIOS supply chain, the exposure to the downstream affects the dozen manufacturers.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.