VendorsAmimegarac_sp-xany version
Vulnerabilities

Ami MegaRAC SP-X any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-54085
Redfish Authentication Bypass
Published 2025-03-11 · Analyzed
10.0KEVEPSS 0.607
CVE-2023-37293
stack-based buffer overflow
Published 2024-01-09 · Modified
9.6EPSS 0.003
CVE-2023-3043
Stack-based Buffer Overflow BMC
Published 2024-01-09 · Modified
9.6EPSS 0.003
CVE-2023-34342
AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure, or data tampering.
Published 2023-06-12 · Modified
9.1EPSS 0.005
CVE-2023-34334
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering.  
Published 2023-06-12 · Modified
8.8EPSS 0.008
CVE-2023-34343
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering.
Published 2023-06-12 · Modified
8.8EPSS 0.008
CVE-2023-34341
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure, or data tampering.
Published 2023-06-12 · Modified
8.8EPSS 0.008
CVE-2023-34336
AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may lead to code execution, denial of service, or escalation of privileges.  
Published 2023-06-12 · Modified
8.8EPSS 0.007
CVE-2023-37294
Heap-based Buffer Overflow
Published 2024-01-09 · Modified
8.8EPSS 0.003
CVE-2023-37295
Heap-based Buffer Overflow
Published 2024-01-09 · Modified
8.8EPSS 0.003
CVE-2023-37296
Stack-based Buffer Overflow
Published 2024-01-09 · Modified
8.8EPSS 0.003
CVE-2023-37297
heap memory overflow
Published 2024-01-09 · Modified
8.8EPSS 0.003
CVE-2023-34332
Untrusted Pointer Dereference in BMC
Published 2024-01-09 · Modified
7.8EPSS 0.002
CVE-2023-34333
Untrusted Pointer Dereference
Published 2024-01-09 · Modified
7.8EPSS 0.002
CVE-2023-34345
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to information disclosure.
Published 2023-06-12 · Modified
6.5EPSS 0.007
CVE-2023-34344
A vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username
Published 2023-06-12 · Modified
5.3EPSS 0.005