CVE-2022-40258: Weak password hashes for Redfish & API
Published Jan 31, 2023
·Updated
AMI Megarac Weak password hashes for Redfish & API
Affected Software
2 affected components
AMI Megarac Spx-12<7.00
AMI Megarac Spx-13<5.00
Remediation
Information
AMI-SA-2023001
Event History
Jan 31, 2023
CVE Published
via MITRE·12:53 AM
Data Sourced
via MITRE·12:53 AM
RemedyDescriptionSeverityWeakness
Mar 18, 2025
News Published
via BleepingComputer·03:29 PM
News Published
via BleepingComputer·03:30 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-40258?
The severity of CVE-2022-40258 is medium.
2
Which software is affected by CVE-2022-40258?
AMI Megarac Spx-12 version up to-exclusive 7.00 and AMI Megarac Spx-13 version up to-exclusive 5.00 are affected by CVE-2022-40258.
3
How can I fix CVE-2022-40258?
To fix CVE-2022-40258, update AMI Megarac Spx-12 to version 7.00 or above and AMI Megarac Spx-13 to version 5.00 or above.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-40258?
The CWE for CVE-2022-40258 is CWE-916.
5
Where can I find more information about CVE-2022-40258?
You can find more information about CVE-2022-40258 in the following references: [Security Advisory by AMI](https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023001.pdf), [Security Advisory by NetApp](https://security.netapp.com/advisory/ntap-20230731-0008/).