CVE-2022-2827: AMI MegaRAC User Enumeration Vulnerability
Published Dec 5, 2022
·Updated
AMI MegaRAC User Enumeration Vulnerability
Affected Software
2 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
Remediation
Information
AMI-SA-2023001
Event History
Dec 5, 2022
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
RemedyDescriptionSeverityWeakness
Mar 18, 2025
News Published
via BleepingComputer·03:29 PM
News Published
via BleepingComputer·03:30 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2022-2827?
CVE-2022-2827 is the identifier for the AMI MegaRAC User Enumeration Vulnerability.
2
What is the affected software?
The affected software is AMI MegaRAC SP-X versions 12 and 13.
3
What is the severity of CVE-2022-2827?
The severity of CVE-2022-2827 is high with a CVSS score of 7.5.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to enumerate valid user accounts on the affected AMI MegaRAC SP-X servers.
5
Is there a fix available for CVE-2022-2827?
Yes, please refer to the official security advisory for instructions on how to apply the necessary updates or patches to mitigate this vulnerability.