CVE-2023-34344: A vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username
Published Jun 12, 2023
·Updated
AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.
Affected Software
2 affected components
AMI Megarac Sp-x>=12.0<12.7
AMI Megarac Sp-x>=13.0<13.5
Event History
Jun 12, 2023
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-34344.
2
What is the severity rating of CVE-2023-34344?
The severity rating of CVE-2023-34344 is medium, with a severity value of 5.3.
3
What is the affected software?
The affected software is AMI BMC Megarac Sp-x versions 12.0 to 12.7 and versions 13.0 to 13.5.
4
What is the impact of this vulnerability?
This vulnerability in the AMI BMC IPMI handler may lead to information disclosure.
5
Where can I find more information about CVE-2023-34344?
More information about CVE-2023-34344 can be found in the security advisory at: [link](https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023005.pdf)