Monday, 12 Jan 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware
Global Market

As clock ticks, vendors slowly patch critical flaw in AMI MegaRAC BMC firmware

Last updated: April 28, 2025 2:07 am
Published April 28, 2025
Share
Portrait of Worried Professional Programmer Fixing a Bug, Dealing with Crashing System. Young Black Man Looking at Big Digital Screens Glitching While Displaying Code Lines, Thinking of Solutions
SHARE

Dell, alternatively, has confirmed that its techniques are unaffected by the MegaRAC concern, because it makes use of its personal Built-in Dell Distant Entry Controller (iDRAC) in its servers.

How might attackers exploit the flaw?

Every week after the patch was posted by AMI in March, Eclypsium, the corporate that discovered the vulnerability in late 2024, printed extra details of its internal workings:

“To our data, the vulnerability solely impacts AMI’s BMC software program stack. Nonetheless, since AMI is on the high of the BIOS provide chain, the downstream affect impacts over a dozen producers,” wrote Eclypsium researchers.

The flaw, scored on the most severity of 10, is designated a ‘crucial’ flaw on CVSS. It might permit bypass authentication by means of the Redfish interface, based on Eclypsium, with a range of outcomes, together with distant management of the server, deployment of malware/ransomware, and harmful actions akin to unstoppable reboot loops and even bricked motherboards.

Briefly, it will not be a superb day for victims, though no exploitation of the vulnerability has up to now been detected. However as with every software program vulnerability, what counts is the pace and ease with which it’s patched.

The primary concern illustrated by the apparently sluggish response to CVE-2024-54085 is the complexity of the patching course of when the software program concerned is a part of a provide chain involving a couple of vendor.

Source link

See also  Amazon and SAP partner on European data sovereignty platforms to offer better oversight
TAGGED: AMI, BMC, clock, Critical, firmware, flaw, MegaRAC, patch, slowly, Ticks, Vendors
Share This Article
Twitter Email Copy Link Print
Previous Article MCG acquires DVM Power + Control MCG acquires DVM Power + Control
Next Article RTA RTA Raises Series A Funding from Susquehanna Growth Equity
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Structurally reprogrammable magnetic metamaterials hold promise for biomedicine, soft robotics

Lively and passive reprogrammable influence response. Credit score: Superior Supplies (2025). DOI: 10.1002/adma.202412353 Scientists from…

May 7, 2025

The risks and rewards of generative AI in software development

Be part of us in Atlanta on April tenth and discover the panorama of safety…

March 31, 2024

New Compute Exchange service answers GPU pricing queries

Compute Trade and Silicon Information, Bochev added “are additionally engaged on growing clearer benchmarks for…

August 14, 2025

Cytonic Raises $8.3M in Seed Funding

Cytonic, a Street City, British Virgin Islands-based multi-virtual-machine blockchain firm, raised $8.3M in Seed funding.…

November 7, 2024

A Recent History of the World’s Fastest Supercomputers

For a few years, exascale was the supercomputing trade’s Holy Grail. For the reason that first petascale…

June 25, 2024

You Might Also Like

Engineer
Global Market

AI, edge, and security: Shaping the need for modern infrastructure management

By saad
AWS logo on wall
Global Market

AWS hikes prices for EC2 Capacity Blocks amid soaring GPU demand

By saad
Portrait of Two Diverse Developers Working on Computers, Typing Lines of Code that Appear on Big Screens Surrounding Them. Male and Female Programmers Creating Innovative Software, Fixing Bugs.
Global Market

At CES, Nvidia launches Vera Rubin platform for AI data centers

By saad
Middle Aged Bearded Senior Project Manager Stands Next to Big Screen with Neural Network. Professional Computer Data Science Engineer Work in a System Control and Monitoring Telecommunications Office
Global Market

Ethernet groups keep 2026 focus on higher bandwidth, AI demands

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.