Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 60.8%; technical severity is CVSS 10.0.
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Who should care
- Teams operating Megarac Sp-x, MegaRAC SPx, H300s Firmware +8 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Megarac Sp-x, MegaRAC SPx, H300s Firmware +8 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Vendor advisory from go.ami.com
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE
- CWE-290
- Affected versions
- AMI Megarac Sp-x (Start Including 12, End Excluding 12.7 | Start Including 13, End Excluding 13.5); AMI MegaRAC SPx; Netapp H300s Firmware (Version -); Netapp H410c Firmware (Version -); Netapp H410s Firmware (Version -); Netapp H500s Firmware (Version -); Netapp H700s Firmware (Version -); Netapp Sg110 Firmware (Version -)
- Fixed versions
- AMI Megarac Sp-x (Fixed from 12.7, 13.5)
- Published
- 11 March 2025
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 60.8%
- Signal calculated at 81
External references
- NIST Government advisory CVE-2024-54085
- CISA Government advisory CVE-2024-54085
- Go Ami Technical reference AMI SA 2025003.pdf
- Arstechnica Exploit information Active Exploitation Of Ami Management Tool Imperils Thousands Of Servers
- Eclypsium Exploit information CVE-2024-05485
- Security Netapp Third-party advisory Ntap 20250328 0003
- Bleepingcomputer Exploit information Cisa Ami Megarac Bug That Lets Hackers Brick Servers Now Actively Exploited
- Networkworld Exploit information Ami Megarac Authentication Bypass Flaw Is Being Exploitated Cisa Warns