CVE-2024-54085

EUVD-2024-54252
AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerability may lead to a loss of confidentiality, integrity, and/or
availability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
AMICNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
amimegarac_sp-x
12 ≤
𝑥
< 12.7
amimegarac_sp-x
13 ≤
𝑥
< 13.5
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
netappsg6160_firmware
-
netappsgf6112_firmware
-
netappsg110_firmware
-
netappsg1100_firmware
-
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
amimegarac_spx
12.0 ≤
𝑥
< 12.7
CNA
amimegarac_spx
13.0 ≤
𝑥
< 13.5
CNA