Skip to content
Noroxi

AMI records

62 published records for vendor ami.

Researcher profile

Entered KEV
1 · 1.6%
Weaponized
1 · 1.6%
Pre-auth RCE
0
With a fix record
45.2%
Median publish → KEV
106 days

All records

62 records
  • Redfish Authentication Bypass

    CriticalCVSS 10.0KEVWeaponizedEPSS 61%

    ami · megarac sp-xMar 11, 2025

  • MegaRAC Default Credentials Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    ami · megarac sp-xDec 5, 2022

  • MegaRAC Default Credentials Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    ami · megarac sp-xDec 5, 2022

  • hard coded cryptographic key

    CriticalCVSS 9.8No exploitEPSS 0%

    ami · megarac sp-xJul 5, 2023

  • AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances,

    CriticalCVSS 9.1No exploitEPSS 1%

    ami · megarac sp-xJun 12, 2023

  • AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secur

    CriticalCVSS 9.1No exploitEPSS 0%

    ami · megarac spxJun 12, 2023

  • AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.

    CriticalCVSS 9.1No exploitEPSS 0%

    ami · megarac sp-xApr 18, 2023

  • AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, wh

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJun 12, 2023

  • AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, wh

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJun 12, 2023

  • Runtime Service Access outside SMRAM

    HighCVSS 8.8No exploitEPSS 1%

    ami · aptio vNov 12, 2024

  • AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locatio

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJun 12, 2023

  • Password reset interception via API

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJan 30, 2023

  • AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJun 12, 2023

  • Code injection via Dynamic Redfish Extension interface

    HighCVSS 8.8No exploitEPSS 1%

    ami · megarac sp-xJul 18, 2023

  • Stack overflow vulnerability in SMI handler on SmmSmbiosElog.

    HighCVSS 8.8No exploitEPSS 0%

    intel · nuc m15 laptop kit lapbc510 firmwareSep 20, 2022

  • Usage of Hard-coded Credentials

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJul 5, 2023

  • CVE-2023-3043
    35Monitor

    Stack-based Buffer Overflow BMC

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • stack-based buffer overflow

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • Heap-based Buffer Overflow

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • Heap-based Buffer Overflow

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • Stack-based Buffer Overflow

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • heap memory overflow

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJan 9, 2024

  • Inadequate Encryption Strength

    HighCVSS 8.8No exploitEPSS 0%

    ami · megarac sp-xJul 5, 2023

  • Authentication Bypass via HTTP Header Spoofing

    HighCVSS 8.0No exploitEPSS 1%

    ami · megarac sp-xJul 18, 2023

  • The stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.

    HighCVSS 8.2No exploitEPSS 0%

    intel · nuc m15 laptop kit lapbc510 firmwareSep 20, 2022