CVE-2024-54085 AMI MegaRAC BMC auth-bypass via Redfish; added to CISA KEV 25 Jun 2025; OEM'd across 12+ server vendors
CVSS 10.0observed
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| As of | 2025-06-25 |
| Source | NVD (CVSS v4.0 10.0) / CISA KEV alert 25 Jun 2025 / Eclypsium · Description; CVSS v4.0 CNA score 10.0; CISA KEV section showing addition on June 25, 2025 |
| Review | checking…review by 2026-08-04 · standard cadence |
| Recorded changes | last 2026-07-03 · 2 revisions tracked |
| Claim id | cve-2024-54085-ami-megarac-bmc-auth-bypass-via |
Where the guide uses it
← Full numbers register — every date-stamped figure in the guide, with revision history.