Lucene search

K
nvd[email protected]NVD:CVE-2023-34341
HistoryJun 12, 2023 - 5:15 p.m.

CVE-2023-34341

2023-06-1217:15:10
CWE-119
web.nvd.nist.gov
ami bmc
spx rest api
code execution
data tampering
information disclosure
denial of service
memory context
ipmi server process

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can read and write to arbitrary locations
within the memory context of the IPMI server process, which may lead to code
execution, denial of service, information disclosure, or data tampering.

Affected configurations

NVD
Node
amimegarac_sp-xRange12.012.7
OR
amimegarac_sp-xRange13.013.5

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Related for NVD:CVE-2023-34341