Vulnerabilities > AMI
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-18 | CVE-2023-28863 | Insufficient Verification of Data Authenticity vulnerability in AMI Megarac Sp-X 12/13 AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity. | 9.1 |
2023-02-15 | CVE-2023-25191 | Insufficiently Protected Credentials vulnerability in AMI Megarac Sp-X 12/13 AMI MegaRAC SPX devices allow Password Disclosure through Redfish. | 7.5 |
2023-02-15 | CVE-2023-25192 | Exposure of Resource to Wrong Sphere vulnerability in AMI Megarac Sp-X 12/13 AMI MegaRAC SPX devices allow User Enumeration through Redfish. | 5.3 |
2023-01-31 | CVE-2022-40258 | Use of Password Hash With Insufficient Computational Effort vulnerability in AMI Megarac Spx-12 and Megarac Spx-13 AMI Megarac Weak password hashes for Redfish & API | 5.3 |
2023-01-30 | CVE-2022-26872 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in AMI Megarac Sp-X 12/13 AMI Megarac Password reset interception via API | 8.8 |
2022-12-05 | CVE-2022-2827 | Unspecified vulnerability in AMI Megarac Sp-X 12/13 AMI MegaRAC User Enumeration Vulnerability | 7.5 |
2022-12-05 | CVE-2022-40242 | Improper Authentication vulnerability in AMI Megarac Sp-X 12/13 MegaRAC Default Credentials Vulnerability | 9.8 |
2022-12-05 | CVE-2022-40259 | Improper Authentication vulnerability in AMI Megarac Sp-X 12/13 MegaRAC Default Credentials Vulnerability | 9.8 |
2022-09-20 | CVE-2022-26873 | Out-of-bounds Write vulnerability in multiple products A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. | 8.2 |
2022-09-20 | CVE-2022-40250 | Out-of-bounds Write vulnerability in multiple products An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. | 8.8 |