A vulnerability has been discovered in AMI MegaRAC Software, which could allow for remote code execution. MegaRAC is a product line of BMC firmware packages and formerly service processors providing out-of-band, or lights-out remote management of computer systems. Successful exploitation of this vulnerability allows an attacker to remotely control the compromised server, remotely deploy malware, ransomware, firmware tampering, bricking motherboard components (BMC or potentially BIOS/UEFI), potential server physical damage (over-voltage / bricking), and indefinite reboot loops that a victim cannot stop.
More Stories
workrave-1.10.53-1.el8
FEDORA-EPEL-2025-93f69f60e4 Packages in this update: workrave-1.10.53-1.el8 Update description: Fixing CVE-2023-2142 Read More
DSA-5906-1 erlang – security update
Several vulnerabilities were discovered in the Erlang/OTP implementation of the SSH protocol, which may result in denial of service or...
caddy-2.10.0-1.fc42
FEDORA-2025-4518c12e2f Packages in this update: caddy-2.10.0-1.fc42 Update description: Update to version 2.10.0. Aside from the new upstream features, this update...
nextcloud-29.0.16-1.el9
FEDORA-EPEL-2025-9129f1f736 Packages in this update: nextcloud-29.0.16-1.el9 Update description: 29.0.16 release RHBZ#2345763 Read More
chromium-135.0.7049.95-1.fc42
FEDORA-2025-fb323a2b22 Packages in this update: chromium-135.0.7049.95-1.fc42 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc40
FEDORA-2025-7827e4feac Packages in this update: chromium-135.0.7049.95-1.fc40 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...