CISA KEV · catalog date Jun 25, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-54085
Redfish Authentication Bypass
Exploited in the wild (CISA KEV since Jun 25, 2025). AMI reports CVSS 4.0 10.0. EPSS estimates 60.7% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
- State
- PUBLISHED
- Published
- Mar 11, 2025
- Updated
- Feb 26, 2026
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAAMIOriginal evidence ↗
Record text: Redfish Authentication Bypass
Inspect raw assertion
- Field
container- Value
- Redfish Authentication Bypass
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 60.75% probability · 99.08th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.607470000000; percentile 0.990820000000
FIRST EPSS · score date Aug 27, 2026 · 99.1th percentile · first observed Aug 27, 2026
AMI · CVSS 4.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Redfish Authentication Bypass
Inspect raw assertion
- Field
container- Value
- Redfish Authentication Bypass
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
60.75% probability · 99.08th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.607470000000; percentile 0.990820000000
Applicability
Cited product scope
Grouped from 19 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
20 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "12.0", "lessThan": "12.7", "versionType": "RC"}, {"status": "affected", "version": "13.0", "lessThan": "13.5", "versionType": "RC"}]product-c7a4a673d3198e1f2cb10fa181603e0ac74e2d9b7bc225c2861f718000f4b5acLinked exactInspect raw assertions
cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 13; through excluding 13.5
- Match ID
cc09c9c4-f549-4eb7-9ee3-64c4c6e8633d
cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 12; through excluding 12.7
- Match ID
402a5b6d-465c-4cc8-b75c-f96f0de0a67c
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8497a4c9-8474-4a62-8331-3fe862ed4098
product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0b4ad8a-f172-4558-aec6-ff424ba2d912
product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7fff7106-ed78-49ba-9ec5-b889e3685d53
product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b06f4839-d16a-4a61-9bb5-55b13f41e47f
product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56409cec-5a1e-4450-aa42-641e459cc2af
product-f9bcd9490498ea413b96352cfc68044f29f4389109b214a163a3b4b440ca883eLinked exactInspect raw assertion
cpe:2.3:h:netapp:sg110:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
083478ba-3640-4a85-8114-07bc1fe083d7
product-a81b059e371230274ba8840a67e01388aac28f3569604629826197194710d25cLinked exactInspect raw assertion
cpe:2.3:h:netapp:sg1100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
379cf2e2-d43b-4dd1-aaba-885397bb7d64
product-9c8202cb255bfd64293743c92fcf683e5a618779104f18157dd6e135d7baac2bLinked exactInspect raw assertion
cpe:2.3:o:netapp:sg1100_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
81305b7c-0070-4b4d-8b0c-34ad60e58994
product-df9c879782953b2174bd850096c411b8b8f3176fa46f11ed8f1b4642131f8f80Linked exactInspect raw assertion
cpe:2.3:o:netapp:sg110_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1ac09386-d8c1-4eef-8e21-afcae3891510
product-f96c92a3b878b08475843c9fdefba924234addf60125ebf5ac2d01a6170f3366Linked exactInspect raw assertion
cpe:2.3:h:netapp:sg6160:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f84b8a44-fc01-4211-b5b3-a0931f9e82cc
product-423c43c446862d40dff035611205dc9acc30dd5f99dab8597a131763721e3afdLinked exactInspect raw assertion
cpe:2.3:o:netapp:sg6160_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
503414b6-66ed-4280-bba7-8ce250f1049a
product-65c706c71153912a537eb2dbc35e56a5a45ca7ac4a9e66fa5c448c2c999164eaLinked exactInspect raw assertion
cpe:2.3:h:netapp:sgf6112:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5b1323e5-8c23-42d3-94fb-d06d5eadf278
product-1d67455e1d2ed78b191d8e626b5e19785bfacf1649d213e9192ba8e4a71b181aLinked exactInspect raw assertion
cpe:2.3:o:netapp:sgf6112_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12bd7c95-1574-4414-80f3-f17bd75dfefe
Affected-product evidence
Accepted scope and product mapping
10 canonical links · 1 source-reported links
vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1d67455e1d2ed78b191d8e626b5e19785bfacf1649d213e9192ba8e4a71b181a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
100c962e-e9e3-4209-9d07-b123837db3b6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3b66a712-aa0f-46d5-bb90-f125515fe870vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
31370b06-7a8e-49ad-8555-f629d9a5e527vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-423c43c446862d40dff035611205dc9acc30dd5f99dab8597a131763721e3afd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e24567ad-40fc-42a8-af14-6a51e59e531evendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-9c8202cb255bfd64293743c92fcf683e5a618779104f18157dd6e135d7baac2b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
333abb3f-df74-455f-924f-29c06950e8c9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0760aa15-ca88-4409-8309-0bd817e2ecf5vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1e1737b1-0b83-4eac-96d5-55a65f87c8bevendor-1355dc0916809e9900ec18aad1b572c1f9d16ee4f0f0761ebc1133b3be8a3bfb · product-c7a4a673d3198e1f2cb10fa181603e0ac74e2d9b7bc225c2861f718000f4b5ac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a3d6c094-7c27-4ddc-9d9c-cfae2d320b08cc35e864-34a8-41c9-af72-599aa4da4aebvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-df9c879782953b2174bd850096c411b8b8f3176fa46f11ed8f1b4642131f8f80
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4fd08c59-d62c-4a8f-9dcf-a76c82d22480vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b82f0183-30a9-4453-a541-2f7e4358c407Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2e58f985-496f-4e4b-84cc-9f9476d47beeAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDirect CVE/CNA normalized decisions
AMI
CVSS 4.0 · Primary · Original assertion · rank 1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H- Validation
- Valid match
- Recomputed
- 10.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.