First published: Mon Jun 12 2023(Updated: )
AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure, or data tampering.
Credit: biossecurity@ami.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ami Megarac Sp-x | >=12.0<12.7 | |
Ami Megarac Sp-x | >=13.0<13.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-34342.
The severity of CVE-2023-34342 is critical with a CVSS score of 9.1.
The affected software is Ami Megarac Sp-x versions 12.0 to 12.7 and versions 13.0 to 13.5.
The potential impact of this vulnerability includes denial of service, escalation of privileges, information disclosure, or data tampering.
Please refer to the security advisory linked in the references section for information on how to fix this vulnerability.