CVE-2023-25191: High severity ami megarac spx vulnerability
Published Feb 15, 2023
·Updated
AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.
Affected Software
2 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-25191?
CVE-2023-25191 refers to a vulnerability in AMI MegaRAC SPX devices that allows Password Disclosure through Redfish.
2
What is the severity of CVE-2023-25191?
CVE-2023-25191 has a severity rating of 7.5, which is considered high.
3
How can the AMI MegaRAC SPX devices be affected by CVE-2023-25191?
AMI MegaRAC SPX devices running versions 12 and 13 are affected by CVE-2023-25191.
4
What are the fixed versions for CVE-2023-25191?
The fixed versions for CVE-2023-25191 are SPx_12-update-7.00 and SPx_13-update-5.00.
5
How can I fix the vulnerability CVE-2023-25191?
To fix CVE-2023-25191, update your AMI MegaRAC SPX device to versions SPx_12-update-7.00 or SPx_13-update-5.00.