CVE-2023-34472: CRLF Injection
Published Jul 5, 2023
·Updated
AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in HTTP Headers. A successful exploit of this vulnerability may lead to a loss of integrity.
Affected Software
2 affected components
AMI Megarac Sp-x=12
AMI Megarac Sp-x=13
Event History
Jul 5, 2023
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this AMI SPx vulnerability?
The vulnerability ID for this AMI SPx vulnerability is CVE-2023-34472.
2
What is the severity of CVE-2023-34472?
The severity of CVE-2023-34472 is medium with a CVSS score of 6.5.
3
What is the affected software of CVE-2023-34472?
The affected software of CVE-2023-34472 is AMI Megarac Sp-x versions 12 and 13.
4
What is the impact of CVE-2023-34472?
A successful exploit of CVE-2023-34472 may lead to a loss of integrity.
5
How can I fix CVE-2023-34472?
There is currently no known fix for CVE-2023-34472. It is recommended to follow the mitigation steps provided in the security advisory.