CVE-2023-34338: hard coded cryptographic key
Published Jul 5, 2023
·Updated
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
Affected Software
2 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
Event History
Jul 5, 2023
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this AMI SPx vulnerability?
The vulnerability ID is CVE-2023-34338.
2
What is the severity of CVE-2023-34338?
The severity of CVE-2023-34338 is critical with a CVSS score of 9.8.
3
What is the affected software by CVE-2023-34338?
The affected software is Ami Megarac Sp-x version 12 and 13.
4
What is the impact of CVE-2023-34338?
A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
5
How can I fix CVE-2023-34338?
To fix CVE-2023-34338, refer to the security advisory provided by the vendor for appropriate mitigation steps.