Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MegaRAC_SPx — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in MegaRAC_SPx, with AI-generated Chinese analysis, references, and POCs.

This page presents a comprehensive vulnerability aggregation report for MegaRAC_SPx, focusing on Common Weakness Enumerations associated with this specific vendor and product line. It serves as a centralized repository for security professionals to review known weaknesses and their corresponding exploitability metrics within the MegaRAC_SPx ecosystem. The content collected here encompasses a wide range of vulnerability types, including remote code execution, authentication bypasses, information disclosure, and cross-site scripting flaws. The time range covered spans from the initial public disclosure of security issues up to the most recent patches released by the vendor. This ensures that users have access to both legacy risks that may still persist in unpatched environments and emerging threats that require immediate attention. By consolidating data from various sources, the page provides a holistic view of the security posture of MegaRAC_SPx over time. Here, you can track vendor advisories to stay informed about critical updates and mitigation strategies. The platform allows you to understand specific weakness classes by providing detailed descriptions and impact analyses for each identified flaw. Additionally, you can look up a product's vulnerability history to assess long-term security trends and evaluate the effectiveness of past remediation efforts. This historical perspective is crucial for risk assessment and planning future security audits or compliance reviews. By utilizing this resource, stakeholders can make data-driven decisions regarding system hardening, patch management, and overall infrastructure security, ensuring that MegaRAC_SPx deployments remain resilient against known attack vectors.

Vendor: AMI

CVE IDTitleCVSSSeverityPublished
CVE-2023-37297 heap memory overflow CWE-122 8.3 High2024-01-09
CVE-2023-37296 Stack-based Buffer Overflow CWE-121 8.3 High2024-01-09
CVE-2023-37295 Heap-based Buffer Overflow CWE-122 8.3 High2024-01-09
CVE-2023-37294 Heap-based Buffer Overflow CWE-122 8.3 High2024-01-09
CVE-2023-37293 stack-based buffer overflow CWE-121 9.6 Critical2024-01-09
CVE-2023-34333 Untrusted Pointer Dereference CWE-822 7.8 High2024-01-09
CVE-2023-3043 Stack-based Buffer Overflow BMC CWE-121 9.6 Critical2024-01-09
CVE-2023-34332 Untrusted Pointer Dereference in BMC CWE-822 7.8 High2024-01-09
CVE-2023-34473 Usage of Hard-coded Credentials CWE-798 6.6 Medium2023-07-05
CVE-2023-34472 AMI MegaRAC 安全漏洞 CWE-113 5.7 Medium2023-07-05
CVE-2023-34471 Missing Cryptographic Step CWE-325 6.3 Medium2023-07-05
CVE-2023-34338 hard coded cryptographic key CWE-321 7.1 High2023-07-05
CVE-2023-34337 Inadequate Encryption Strength CWE-326 7.6 High2023-07-05
CVE-2023-34336 BMC AMI 安全漏洞 CWE-120 8.1 High2023-06-12
CVE-2023-34335 BMC AMI 访问控制错误漏洞 CWE-288 7.7 High2023-06-12
CVE-2023-34334 BMC AMI 操作系统命令注入漏洞 CWE-78 7.2 High2023-06-12
CVE-2023-34343 BMC AMI 操作系统命令注入漏洞 CWE-78 7.2 High2023-06-12
CVE-2023-34342 BMC AMI 路径遍历漏洞 CWE-22 6.0 Medium2023-06-12
CVE-2023-34341 BMC AMI 缓冲区错误漏洞 CWE-119 7.2 High2023-06-12
CVE-2023-34345 BMC AMI 路径遍历漏洞 CWE-22 6.5 Medium2023-06-12
CVE-2023-34344 A vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username CWE-203 5.3 Medium2023-06-12

All 21 known CVE vulnerabilities affecting MegaRAC_SPx with full Chinese analysis, references, and POCs where available.