First published: Mon Jan 30 2023(Updated: )
AMI Megarac Password reset interception via API
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ami Megarac Sp-x | =12 | |
Ami Megarac Sp-x | =13 |
See AMI-SA-2023001
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26872 refers to a vulnerability in AMI Megarac SP-X that allows for interception of password reset requests via the API.
CVE-2022-26872 has a severity keyword of 'high' and a CVSS score of 8.8, indicating a significant security risk.
CVE-2022-26872 affects versions 12 and 13 of AMI Megarac SP-X, allowing an attacker to intercept password reset requests through the API.
Yes, a fix is available for CVE-2022-26872. It is recommended to refer to the vendor's security advisory for specific steps to mitigate the vulnerability.
More information about CVE-2022-26872 can be found in the vendor's security advisory and the NetApp advisory linked in the references.