AMI MegaRAC SPx Redfish Authentication Bypass Vulnerability

CVE-2024-54085
Apr 25, 2025

Giga Computing Technology Co., Ltd. is aware of the recently disclosed BMC&C vulnerability by Eclypsium, identified as CVE-2024-54085, with a CVSS v4.0 score of 10.0. Updated firmware addressing this issue will be available for download on the corresponding product pages.

 

Model

Patched Firmware Version

GIGABYTE servers & motherboards with AST2500 BMC and VGA ports

12.61.35 or later

GIGABYTE servers & motherboards with AST2500 BMC and Mini-DP

12.83.51 or later

GIGABYTE servers & motherboards with AST2500 BMC (Arm platform)

Scheduled for release in WW18

GIGABYTE servers & motherboards with AST2600 BMC

13.06.01 or later

 

 

*Please navigate to the "Support" section of the relevant product page to download the updated firmware.

*For any further assistance regarding this issue please contact your Giga Computing sales representative, or create a new support ticket at https://esupport.gigabyte.com