Lucene search

K
cve[email protected]CVE-2023-34341
HistoryJun 12, 2023 - 5:15 p.m.

CVE-2023-34341

2023-06-1217:15:10
CWE-119
web.nvd.nist.gov
15
ami
bmc
vulnerability
spx rest api
code execution
denial of service
information disclosure
data tampering

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can read and write to arbitrary locations
within the memory context of the IPMI server process, which may lead to code
execution, denial of service, information disclosure, or data tampering.

Affected configurations

NVD
Node
amimegarac_sp-xRange12.012.7
OR
amimegarac_sp-xRange13.013.5

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "platforms": [
      "ARM"
    ],
    "product": "MegaRAC_SPx",
    "vendor": "AMI",
    "versions": [
      {
        "lessThan": "12.7",
        "status": "affected",
        "version": "12.0",
        "versionType": "RC"
      },
      {
        "lessThan": "13.5",
        "status": "affected",
        "version": "13.0",
        "versionType": "RC"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

Related for CVE-2023-34341