CVE detail
CVE-2023-34330
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
The frequency and severity of security issues found over the years in the firmware of baseboard management controllers (BMCs) present in server motherboards highlight an often overlooked, yet critical area of IT infrastructure security. The latest addition to the growing list of flaws are two vulnerabilities in a widely used “lights-out” management interface used by […]
newswww.csoonline.comJul 28, 2023, 9:22 PM- New AMI BMC Flaws Allowing Takeover and Physical Damage Could Impact Millions of DevicesSecurityWeek
Two new serious vulnerabilities in AMI BMC, which is used by millions of devices, can allow attackers to take control of systems and cause physical damage.
newswww.securityweek.comJul 20, 2023, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-72676CVSS 6.5 · Medium
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Ki…
- CVE-2026-73651CVSS 5.7 · Medium
TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.…
- CVE-2026-73649CVSS 9.8 · Critical
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototyp…
- CVE-2026-73505CVSS 7.8 · High
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which i…
- CVE-2026-67986CVSS 8.4 · High
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method contai…
- CVE-2026-61962CVSS 10.0 · Critical
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.