Sunday, 15 Jun 2025
Subscribe
logo logo
  • Global
  • Technology
  • Business
  • AI
  • Cloud
  • Edge Computing
  • Security
  • Investment
  • More
    • Sustainability
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
  • 🔥
  • data
  • Secures
  • Funding
  • revolutionizing
  • Investment
  • Center
  • Series
  • cloud
  • Power
  • Future
  • Centers
  • million
Font ResizerAa
Silicon FlashSilicon Flash
Search
  • Global
  • Technology
  • Business
  • AI
  • Cloud
  • Edge Computing
  • Security
  • Investment
  • More
    • Sustainability
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Silicon Flash > Blog > Global Market > As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware
Global Market

As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware

Published April 28, 2025 By Juwan Chacko
Share
2 Min Read
As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware
SHARE

Dell has reassured its customers that its systems are not impacted by the MegaRAC vulnerability. This is because Dell utilizes its own Integrated Dell Remote Access Controller (iDRAC) in its servers.

How could cyber attackers take advantage of this vulnerability? Eclypsium, the company that uncovered the flaw in 2024, provided additional insights into the issue a week after the patch was released by AMI. According to Eclypsium researchers, the vulnerability primarily affects AMI’s BMC software stack, which has downstream implications for over a dozen manufacturers due to AMI’s position in the BIOS supply chain.

Rated as a critical flaw with a severity score of 10 on the CVSS scale, the vulnerability enables attackers to bypass authentication via the Redfish interface. This could lead to severe consequences such as remote server control, deployment of malware or ransomware, and destructive actions like unstoppable reboot loops or bricked motherboards.

Despite the potential risks associated with this vulnerability, there have been no reported cases of exploitation thus far. However, the importance of promptly addressing and patching such vulnerabilities cannot be overstated.

One of the key challenges highlighted by the delayed response to CVE-2024-54085 is the intricate nature of the patching process, particularly when multiple vendors are involved in the software supply chain. Effective and timely patching is crucial in mitigating the risks posed by vulnerabilities like the MegaRAC issue.

See also  Data Center Outage Rates Reach Record Lows, According to Uptime Institute
TAGGED: AMI, BMC, clock, critical, firmware, flaw, MegaRAC, patch, slowly, ticks, vendors
Share This Article
Twitter Email Copy Link Print
Previous Article Microsoft rolls out Recall and other AI features to all Copilot+ PCs, nearly a year after unveiling Microsoft rolls out Recall and other AI features to all Copilot+ PCs, nearly a year after unveiling
Next Article World’s most miniature quantum computer unveiled powered by a single photon World’s most miniature quantum computer unveiled powered by a single photon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
LinkedInFollow

Popular Posts

Introducing Traders’ Gym: Your Ultimate Mobile Trading Tool

Summary: 1. ThinkMarkets is launching Traders' Gym, an exclusive backtesting tool, on the ThinkTrader mobile…

June 6, 2025

Don’t Miss Your Final Opportunity to Showcase at TechCrunch Sessions: AI

Don't Miss Out: Last Chance to Secure Your Spot at TechCrunch Sessions: AI Time is…

May 9, 2025

Why the Forecast Is Only Partly Sunny

Summary: Solar power is a cost-effective and clean energy source, but its implementation in data…

May 29, 2025

Google AI model understands dolphin chatter

Google recently introduced an AI model named DolphinGemma, designed to decode the intricate communication of…

April 21, 2025

Navigating the Future: Coping with the U.S.’s AI Job Anxiety

When OpenAI unveiled ChatGPT in late 2023, generative AI was initially seen as a tool…

May 4, 2025

You Might Also Like

Unveiling the Future: OVHcloud’s Quantum Processing Unit-as-a-Service Coming in 2025
Global Market

Unveiling the Future: OVHcloud’s Quantum Processing Unit-as-a-Service Coming in 2025

Juwan Chacko
Massive Google Cloud Outage Causes Widespread Service Disruption for 7+ Hours
Global Market

Massive Google Cloud Outage Causes Widespread Service Disruption for 7+ Hours

Juwan Chacko
Breaking: IBM Announces Plans to Launch Fault-Tolerant Quantum Computer by 2029
Global Market

Breaking: IBM Announces Plans to Launch Fault-Tolerant Quantum Computer by 2029

Juwan Chacko
Revolutionizing High Performance Computing and AI: Ultra Ethernet Consortium Releases 1.0 Specification
Global Market

Revolutionizing High Performance Computing and AI: Ultra Ethernet Consortium Releases 1.0 Specification

Juwan Chacko
logo logo
Facebook Twitter Youtube Rss

About US

Silicon Flash: Stay informed with the latest Tech News, Innovations, Gadgets, AI, Data Center, and Industry trends from around the world—all in one place.

Top Categories
  • Technology
  • Business
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – siliconflash.com – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?