CVE-2023-28863: Critical severity ami megarac spx vulnerability
Published Apr 18, 2023
·Updated
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Affected Software
5 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
Event History
Apr 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Oct 13, 2025
Advisory Published
via F5·04:12 PM
Data Sourced
via F5·04:12 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-28863?
The severity of CVE-2023-28863 is critical (9.1).
2
Which devices are affected by CVE-2023-28863?
AMI MegaRAC SPx12 and SPx13 devices are affected by CVE-2023-28863.
3
What is the vulnerability description of CVE-2023-28863?
CVE-2023-28863 is a vulnerability in AMI MegaRAC SPx12 and SPx13 devices that allows for insufficient verification of data authenticity.
4
How can I fix CVE-2023-28863?
There is no known fix or patch available for CVE-2023-28863 at the moment. It is recommended to follow the guidelines and recommendations provided by AMI and monitor for any updates or patches.
5
Where can I find more information about CVE-2023-28863?
You can find more information about CVE-2023-28863 in the official security advisory by AMI (https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023003.pdf).