Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The new critical vulnerability AMI BMC allows remote server absorption and brick remedy
Global Security

The new critical vulnerability AMI BMC allows remote server absorption and brick remedy

AdminBy AdminMarch 18, 2025No Comments2 Mins Read
AMI BMC Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 18, 2025Red LakshmananVulnerability / firmware safety

AMI BMC vulnerability

The critical safety vulnerability has been disclosed in the MEGARAC AMI (BMC) software management software, which can allow the attacker to bypass authentication and carry out actions after operation.

Vulnerability tracked as Cve-2024-54085Carnate CVSS V4 10.0, indicating the maximum burden.

“Local or remote attacker can use vulnerability by accessing remote control (Redfish) or internal host BMC (Redfish)”, “Company Showare Security Company Eclypsium – Note In a report that shared with Hacker News.

“The operation of this vulnerability allows the attacker to remotely control the compromised server, remotely deploy malicious software, required software, firmware firming, bizarre components of the motherboard (BMC or potentially BIOS / UEFI), potential physical damage to the server Reboot that cannot stop. “

The vulnerability can be armed for devastating attacks, causing the sensitive devices to be constantly restarting, sending malicious teams. Then this can pave the way to uncertain downtime until the devices are re -.

Cybersecurity

The CVE-2024-54085-Apostle in the long list of security deficiencies, which have been found in BMC AMI Megaac since December 2022. They were collectively tracked as BMC & C-

Eclypsium noted that the CVE-2024-54085 is similar to the CVE-2023-34329 because it allows you to undergo authentication with similar impact. The vulnerability has been confirmed what affects the devices below – –

  • HPE Cray XD670
  • Asus RS720A-E11-RS24U
  • Asrockrack

AMI has Released patches To solve the lack of March 11, 2025. While there is no evidence that the problem has been used in the wild, it is important that users down the current update their systems when OEM providers include these fixes and release them to customers.

“Please note that the correction of these vulnerabilities is a non-trivial exercise that requires the downtime of the device,” Ellipseya said. “The vulnerability only affects the BMC AMI software stack. However, because Ami is at the top of the BIOS supply chain, the exposure to the downstream affects the dozen manufacturers.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.