Lucene search

K
cveMitreCVE-2023-25191
HistoryFeb 15, 2023 - 3:15 p.m.

CVE-2023-25191

2023-02-1515:15:11
CWE-522
mitre
web.nvd.nist.gov
39
cve-2023-25191
ami megarac spx
password disclosure
redfish
nvd
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

51.9%

AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.

Affected configurations

Nvd
Node
amimegarac_sp-xMatch12-
OR
amimegarac_sp-xMatch13-
VendorProductVersionCPE
amimegarac_sp-x12cpe:2.3:o:ami:megarac_sp-x:12:-:*:*:*:*:*:*
amimegarac_sp-x13cpe:2.3:o:ami:megarac_sp-x:13:-:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

51.9%

Related for CVE-2023-25191