AMI records
62 published records for vendor ami.
Researcher profile
- Entered KEV
- 1 · 1.6%
- Weaponized
- 1 · 1.6%
- Pre-auth RCE
- 0
- With a fix record
- 45.2%
- Median publish → KEV
- 106 days
Recurring classes
- CWE-20 Improper Input Validation8
- CWE-121 Stack-based Buffer Overflow5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-787 Out-of-bounds Write3
- CWE-122 Heap-based Buffer Overflow3
- CWE-284 Improper Access Control3
The weakness classes this vendor ships most often: where to look.
CWEAll records
62 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
88Now | CVE-2024-54085Weaponized | Redfish Authentication Bypassami · megarac sp-x · CWE-290 | Critical10.0 | KEV | 60.7% | Mar 11, 2025 |
39Monitor | CVE-2022-40242No exploit | MegaRAC Default Credentials Vulnerabilityami · megarac sp-x · CWE-798 | Critical9.8 | — | 0.7% | Dec 5, 2022 |
39Monitor | CVE-2022-40259No exploit | MegaRAC Default Credentials Vulnerabilityami · megarac sp-x · CWE-798 | Critical9.8 | — | 0.6% | Dec 5, 2022 |
39Monitor | CVE-2023-34338No exploit | hard coded cryptographic keyami · megarac sp-x · CWE-321 | Critical9.8 | — | 0.3% | Jul 5, 2023 |
36Monitor | CVE-2023-34342No exploit | AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances,ami · megarac sp-x · CWE-22 | Critical9.1 | — | 0.5% | Jun 12, 2023 |
36Monitor | CVE-2023-34335No exploit | AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing securami · megarac spx · CWE-288 | Critical9.1 | — | 0.4% | Jun 12, 2023 |
36Monitor | CVE-2023-28863No exploit | AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.ami · megarac sp-x · CWE-345 | Critical9.1 | — | 0.4% | Apr 18, 2023 |
35Monitor | CVE-2023-34343No exploit | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whami · megarac sp-x · CWE-78 | High8.8 | — | 0.8% | Jun 12, 2023 |
35Monitor | CVE-2023-34334No exploit | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whami · megarac sp-x · CWE-78 | High8.8 | — | 0.8% | Jun 12, 2023 |
35Monitor | CVE-2024-42442No exploit | Runtime Service Access outside SMRAMami · aptio v · CWE-119 | High8.8 | — | 0.8% | Nov 12, 2024 |
35Monitor | CVE-2023-34341No exploit | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locatioami · megarac sp-x · CWE-119 | High8.8 | — | 0.8% | Jun 12, 2023 |
35Monitor | CVE-2022-26872No exploit | Password reset interception via APIami · megarac sp-x · CWE-640 | High8.8 | — | 0.8% | Jan 30, 2023 |
35Monitor | CVE-2023-34336No exploit | AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may ami · megarac sp-x · CWE-120 | High8.8 | — | 0.7% | Jun 12, 2023 |
35Monitor | CVE-2023-34330No exploit | Code injection via Dynamic Redfish Extension interfaceami · megarac sp-x · CWE-94 | High8.8 | — | 0.6% | Jul 18, 2023 |
35Monitor | CVE-2022-40250No exploit | Stack overflow vulnerability in SMI handler on SmmSmbiosElog.intel · nuc m15 laptop kit lapbc510 firmware · CWE-121 | High8.8 | — | 0.5% | Sep 20, 2022 |
35Monitor | CVE-2023-34473No exploit | Usage of Hard-coded Credentialsami · megarac sp-x · CWE-798 | High8.8 | — | 0.5% | Jul 5, 2023 |
35Monitor | CVE-2023-3043No exploit | Stack-based Buffer Overflow BMCami · megarac sp-x · CWE-121 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-37293No exploit | stack-based buffer overflowami · megarac sp-x · CWE-121 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-37295No exploit | Heap-based Buffer Overflowami · megarac sp-x · CWE-122 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-37294No exploit | Heap-based Buffer Overflowami · megarac sp-x · CWE-122 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-37296No exploit | Stack-based Buffer Overflowami · megarac sp-x · CWE-121 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-37297No exploit | heap memory overflowami · megarac sp-x · CWE-122 | High8.8 | — | 0.3% | Jan 9, 2024 |
35Monitor | CVE-2023-34337No exploit | Inadequate Encryption Strengthami · megarac sp-x · CWE-326 | High8.8 | — | 0.2% | Jul 5, 2023 |
32Monitor | CVE-2023-34329No exploit | Authentication Bypass via HTTP Header Spoofingami · megarac sp-x · CWE-290 | High8.0 | — | 1.2% | Jul 18, 2023 |
32Monitor | CVE-2022-26873No exploit | The stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.intel · nuc m15 laptop kit lapbc510 firmware · CWE-121 | High8.2 | — | 0.4% | Sep 20, 2022 |
- CVE-2024-5408588Now
Redfish Authentication Bypass
CriticalCVSS 10.0KEVWeaponizedEPSS 61%ami · megarac sp-xMar 11, 2025
- CVE-2022-4024239Monitor
MegaRAC Default Credentials Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ami · megarac sp-xDec 5, 2022
- CVE-2022-4025939Monitor
MegaRAC Default Credentials Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%ami · megarac sp-xDec 5, 2022
- CVE-2023-3433839Monitor
hard coded cryptographic key
CriticalCVSS 9.8No exploitEPSS 0%ami · megarac sp-xJul 5, 2023
- CVE-2023-3434236Monitor
AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances,
CriticalCVSS 9.1No exploitEPSS 1%ami · megarac sp-xJun 12, 2023
- CVE-2023-3433536Monitor
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secur
CriticalCVSS 9.1No exploitEPSS 0%ami · megarac spxJun 12, 2023
- CVE-2023-2886336Monitor
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
CriticalCVSS 9.1No exploitEPSS 0%ami · megarac sp-xApr 18, 2023
- CVE-2023-3434335Monitor
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, wh
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJun 12, 2023
- CVE-2023-3433435Monitor
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, wh
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJun 12, 2023
- CVE-2024-4244235Monitor
Runtime Service Access outside SMRAM
HighCVSS 8.8No exploitEPSS 1%ami · aptio vNov 12, 2024
- CVE-2023-3434135Monitor
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locatio
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJun 12, 2023
- CVE-2022-2687235Monitor
Password reset interception via API
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJan 30, 2023
- CVE-2023-3433635Monitor
AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJun 12, 2023
- CVE-2023-3433035Monitor
Code injection via Dynamic Redfish Extension interface
HighCVSS 8.8No exploitEPSS 1%ami · megarac sp-xJul 18, 2023
- CVE-2022-4025035Monitor
Stack overflow vulnerability in SMI handler on SmmSmbiosElog.
HighCVSS 8.8No exploitEPSS 0%intel · nuc m15 laptop kit lapbc510 firmwareSep 20, 2022
- CVE-2023-3447335Monitor
Usage of Hard-coded Credentials
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJul 5, 2023
- CVE-2023-304335Monitor
Stack-based Buffer Overflow BMC
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3729335Monitor
stack-based buffer overflow
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3729535Monitor
Heap-based Buffer Overflow
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3729435Monitor
Heap-based Buffer Overflow
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3729635Monitor
Stack-based Buffer Overflow
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3729735Monitor
heap memory overflow
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJan 9, 2024
- CVE-2023-3433735Monitor
Inadequate Encryption Strength
HighCVSS 8.8No exploitEPSS 0%ami · megarac sp-xJul 5, 2023
- CVE-2023-3432932Monitor
Authentication Bypass via HTTP Header Spoofing
HighCVSS 8.0No exploitEPSS 1%ami · megarac sp-xJul 18, 2023
- CVE-2022-2687332Monitor
The stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.
HighCVSS 8.2No exploitEPSS 0%intel · nuc m15 laptop kit lapbc510 firmwareSep 20, 2022