Lucene search

K
cveCertccCVE-2022-40258
HistoryJan 31, 2023 - 1:15 a.m.

CVE-2022-40258

2023-01-3101:15:11
CWE-916
certcc
web.nvd.nist.gov
34
cve-2022-40258
nvd
ami megarac
weak password hashes
redfish
api

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

34.2%

AMI Megarac Weak password hashes for
Redfish & API

Affected configurations

Nvd
Node
amimegarac_spx-12Range<7.00
OR
amimegarac_spx-13Range<5.00
VendorProductVersionCPE
amimegarac_spx-12*cpe:2.3:o:ami:megarac_spx-12:*:*:*:*:*:*:*:*
amimegarac_spx-13*cpe:2.3:o:ami:megarac_spx-13:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "MegaRAC SPx-12",
    "vendor": "AMI",
    "versions": [
      {
        "lessThanOrEqual": "SPx12-Update-6.00",
        "status": "affected",
        "version": "0",
        "versionType": "Custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "MegaRAC SPx-13",
    "vendor": "AMI",
    "versions": [
      {
        "lessThanOrEqual": "SPx13-Update-4.00",
        "status": "affected",
        "version": "0",
        "versionType": "Custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

34.2%

Related for CVE-2022-40258