CVE-2023-34335: Critical severity AMI MegaRAC SPx vulnerability
Published Jun 12, 2023
·Updated
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections. An exploitation of this vulnerability may lead to a loss of integrity or denial of service.
Affected Software
2 affected components
AMI MegaRAC SPx>=12.0<12.7
AMI MegaRAC SPx>=13.0<13.5
Event History
Jun 12, 2023
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this AMI BMC vulnerability?
The vulnerability ID for this AMI BMC vulnerability is CVE-2023-34335.
2
What is the title of this vulnerability?
The title of this vulnerability is 'AMI BMC contains a vulnerability in the IPMI handler where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections.'
3
What is the severity of vulnerability CVE-2023-34335?
The severity of vulnerability CVE-2023-34335 is critical.
4
What is the affected software?
The affected software is AMI Megarac SPX versions 12.0 to 12.7 and versions 13.0 to 13.5.
5
How can this vulnerability be exploited?
Exploiting this vulnerability may lead to a loss of integrity or denial of service.