CVE-2023-25192: Medium severity ami megarac spx vulnerability
Published Feb 15, 2023
·Updated
AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.
Affected Software
2 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25192.
2
What is the severity of CVE-2023-25192?
The severity of CVE-2023-25192 is medium with a CVSS score of 5.3.
3
What is the affected software?
The affected software is AMI MegaRAC SPX versions 12 and 13.
4
How can User Enumeration be performed through Redfish in AMI MegaRAC SPX devices?
User Enumeration can be performed through Redfish in AMI MegaRAC SPX devices due to a vulnerability.
5
How can I fix CVE-2023-25192?
To fix CVE-2023-25192, update to the fixed versions SPx12-update-7.00 or SPx13-update-5.00.