📦 Megarac Sp X

by Ami

🔍 What is Megarac Sp X?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54085

CRITICAL CVSS 9.8 Mar 11, 2025

CVE-2024-54085 is a critical authentication bypass vulnerability in AMI's SPx BMC firmware that allows remote attackers to gain unauthorized access through the Redfish Host Interface without credentia...

CVE-2023-3043

CRITICAL CVSS 9.6 Jan 9, 2024

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to trigger a stack-based buffer overflow. Successful exploitation could compromise the BMC, potentially leading to complete sy...

CVE-2023-37293

CRITICAL CVSS 9.6 Jan 9, 2024

This vulnerability in AMI's SPx BMC firmware allows attackers on adjacent networks to trigger a stack-based buffer overflow. Exploitation could lead to remote code execution, compromising the BMC's co...

CVE-2023-34329

CRITICAL CVSS 9.1 Jul 18, 2023

This vulnerability in AMI MegaRAC SPx12 BMC allows attackers to bypass authentication by spoofing HTTP headers, potentially gaining unauthorized access to baseboard management controllers. This affect...

CVE-2023-28863

CRITICAL CVSS 9.1 Apr 18, 2023

CVE-2023-28863 is an insufficient verification of data authenticity vulnerability in AMI MegaRAC SPx12 and SPx13 baseboard management controllers (BMCs). This allows attackers to bypass authentication...

CVE-2023-37297

HIGH CVSS 8.3 Jan 9, 2024

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to trigger heap memory corruption via CWE-122 (Heap-based Buffer Overflow). Successful exploitation could compromise the BMC's...

CVE-2023-37295

HIGH CVSS 8.3 Jan 9, 2024

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to cause heap memory corruption, potentially leading to remote code execution or system compromise. It affects systems using v...

CVE-2023-34332

HIGH CVSS 7.8 Jan 9, 2024

This vulnerability in AMI's SPx BMC allows attackers on the local network to exploit an untrusted pointer dereference, potentially compromising the Baseboard Management Controller. This affects system...

CVE-2023-34338

HIGH CVSS 7.1 Jul 5, 2023

AMI SPx BMC firmware contains hard-coded cryptographic keys and certificates, allowing attackers to potentially decrypt sensitive data, impersonate legitimate systems, or compromise BMC functionality....

CVE-2023-25191

HIGH CVSS 7.5 Feb 15, 2023

AMI MegaRAC SPX devices allow password disclosure through Redfish interfaces, enabling attackers to retrieve credentials. This affects organizations using vulnerable AMI MegaRAC SPX devices with Redfi...