CRITICAL🇵🇱 Wersja polska

CVE-2023-37293

CVSS 9.6v3.1pub. 2024-01-09upd. 2024-11-21

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

🤖 AI Analysis
How it works

An attacker with access to an adjacent network can send specially crafted data to the BMC component operating within the AMI MegaRAC SPx software. Improper handling of input data causes a stack-based buffer overflow (CWE-121, CWE-787), which can result in overwriting critical control structures. The attack does not require authentication or user interaction.

Impact

An attacker can gain full control over the BMC component, leading to disclosure of sensitive data, modification of configuration, and disruption or complete unavailability of the device. The vulnerability has an extended scope (Scope: Changed), which means it can affect areas beyond the directly attacked component.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references (AMI-SA-2023010 advisory available on the AMI website). It is also recommended to restrict network access to BMC interfaces exclusively to trusted management network segments and to isolate the BMC management network from production networks.

Who is affected

AMI MegaRAC SPx — versions indicated in manufacturer references (advisory AMI-SA-2023010)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Ami Megarac Sp X

    OS
    Ami
    12 – 12.7 (excl.)13 – 13.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-54085CRITICAL10.0⚠ KEVPL ✓same product

AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC

CVE-2023-3043CRITICAL9.6PL ✓same product

Stack-based buffer overflow w AMI MegaRAC SPx BMC przez sieć lokalną

CVE-2023-34329CRITICAL9.1PL ✓same product

AMI MegaRAC SPx12 BMC — pominięcie uwierzytelnienia przez spoofing nagłówka HTTP

CVE-2023-28863CRITICAL9.1PL ✓same product

AMI MegaRAC SPx — niewystarczająca weryfikacja autentyczności danych

CVE-2023-34332HIGH7.8same product

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to d...