Skip to main content

Vendor archive

ami CVEs

Beta · best-effort

62 CVEs tagged to vendor ami5 Critical, 37 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2025-58770

Published Dec 12, 2025

APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulne…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-33044

Published Oct 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitat…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22833

Published Oct 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of this vulnerability…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22832

Published Oct 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22831

Published Oct 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-33045

Published Sep 9, 2025

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22834

Published Aug 12, 2025

AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resour…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22830

Published Aug 12, 2025

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful exploitation of this vulnerability may lead to resource exhau…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-33043

Published May 29, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of i…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-42446

Published May 13, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54085

Published Mar 11, 2025

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabil…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed

CVE-2024-54084

Published Mar 11, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerabili…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-33659

Published Feb 11, 2025

AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42444

Published Jan 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42442

Published Nov 12, 2024

APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations within the bounds of a memory buffer over the network. A succe…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33660

Published Nov 12, 2024

An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33658

Published Nov 12, 2024

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2315

Published Nov 12, 2024

APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33657

Published Aug 21, 2024

This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33656

Published Aug 21, 2024

The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3043

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability ma…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37297

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37296

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may le…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37295

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37294

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 62 CVEsPage 1 of 3