AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
An attacker with access to an adjacent network can send specially crafted data to the BMC component operating within the AMI MegaRAC SPx software. Improper handling of input data causes a stack-based buffer overflow (CWE-121, CWE-787), which can result in overwriting critical control structures. The attack does not require authentication or user interaction.
An attacker can gain full control over the BMC component, leading to disclosure of sensitive data, modification of configuration, and disruption or complete unavailability of the device. The vulnerability has an extended scope (Scope: Changed), which means it can affect areas beyond the directly attacked component.
Patches available from the manufacturer should be applied in accordance with the references (AMI-SA-2023010 advisory available on the AMI website). It is also recommended to restrict network access to BMC interfaces exclusively to trusted management network segments and to isolate the BMC management network from production networks.
AMI MegaRAC SPx — versions indicated in manufacturer references (advisory AMI-SA-2023010)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAmi Megarac Sp X
OSAmi12 – 12.7 (excl.)13 – 13.6 (excl.)
Related vulnerabilities
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
Stack-based buffer overflow w AMI MegaRAC SPx BMC przez sieć lokalną
AMI MegaRAC SPx12 BMC — pominięcie uwierzytelnienia przez spoofing nagłówka HTTP
AMI MegaRAC SPx — niewystarczająca weryfikacja autentyczności danych
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to d...