Skip to main content

Vendor/product archive

ami / megarac_sp-x CVEs

Beta · best-effort

30 CVEs tagged to ami / megarac_sp-x5 Critical, 18 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-54085

Published Mar 11, 2025

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabil…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed

CVE-2023-3043

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability ma…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37297

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37296

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may le…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37295

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37294

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lea…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37293

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability ma…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34333

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34332

Published Jan 9, 2024

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation of this vulnerability m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34330

Published Jul 18, 2023

AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerabil…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-34329

Published Jul 18, 2023

AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2023-34473

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability may lead to a loss of confiden…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34472

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in HTTP Headers. A successful exploit of this vulnerability ma…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34471

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34338

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerabili…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34337

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34343

Published Jun 12, 2023

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34342

Published Jun 12, 2023

AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, e…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34336

Published Jun 12, 2023

AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may lead to code execution, denial of servi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34334

Published Jun 12, 2023

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34345

Published Jun 12, 2023

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to information disclosure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34344

Published Jun 12, 2023

AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34341

Published Jun 12, 2023

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locations within the memory context of the IPM…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28863

Published Apr 18, 2023

AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25192

Published Feb 15, 2023

AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2