<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — AMI</title><description>Actively exploited vulnerabilities affecting AMI products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/ami.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2024-54085 — AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-54085</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-54085</guid><description>AMI MegaRAC SPx is a baseboard management controller (BMC) firmware used in servers from many major manufacturers. This vulnerability allows an attacker to bypass authentication through spoofing on the Redfish Host Interface — a standard API used for out-of-band server management. Because BMCs operate independently of the main OS and have deep hardware-level access, a successful exploit could give an attacker persistent, low-level control over affected servers, risking full compromise of confidentiality, integrity, and availability.</description><pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate><category>AMI</category><category>MegaRAC SPx</category></item></channel></rss>