Vulnerability Details CVE-2024-54085
AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerability may lead to a loss of confidentiality, integrity, and/or
availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.095
EPSS Ranking 92.5%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Ransomware Campaign
Unknown
Products affected by CVE-2024-54085
-
-
-
-
-
-
cpe:2.3:h:netapp:sg1100:-
-
-
cpe:2.3:h:netapp:sg6160:-
-
cpe:2.3:h:netapp:sgf6112:-
-
cpe:2.3:o:ami:megarac_sp-x:12
-
cpe:2.3:o:ami:megarac_sp-x:13
-
cpe:2.3:o:netapp:h300s_firmware:-
-
cpe:2.3:o:netapp:h410c_firmware:-
-
cpe:2.3:o:netapp:h410s_firmware:-
-
cpe:2.3:o:netapp:h500s_firmware:-
-
cpe:2.3:o:netapp:h700s_firmware:-
-
cpe:2.3:o:netapp:sg1100_firmware:-
-
cpe:2.3:o:netapp:sg110_firmware:-
-
cpe:2.3:o:netapp:sg6160_firmware:-
-
cpe:2.3:o:netapp:sgf6112_firmware:-