CVE-2023-34335

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
12/06/2023
Last modified:
20/06/2023

Description

AMI BMC contains a vulnerability in the IPMI handler, where an<br /> unauthenticated host is allowed to write to a host SPI flash, bypassing secure<br /> boot protections. An exploitation of this vulnerability may lead to a loss of<br /> integrity or denial of service.<br /> <br /> <br /> <br /> <br /> <br />  <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ami:megarac_spx:*:*:*:*:*:*:*:* 12.0 (including) 12.7 (excluding)
cpe:2.3:a:ami:megarac_spx:*:*:*:*:*:*:*:* 13.0 (including) 13.5 (excluding)