Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AMI — Vulnerabilities & Security Advisories 61

Browse all 61 CVE security advisories affecting AMI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AMI, formerly American Megatrends, primarily develops BIOS firmware and embedded software for enterprise servers, workstations, and IoT devices. Its extensive codebase has historically exposed numerous security flaws, resulting in approximately 60 recorded Common Vulnerabilities and Exposures. These defects predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access controls within the firmware interfaces. Notable incidents include critical flaws allowing attackers to bypass authentication mechanisms or execute arbitrary commands with elevated privileges, potentially compromising system integrity. The company has addressed many of these issues through firmware updates, yet the complexity of legacy systems continues to pose risks. Security researchers frequently highlight the importance of regular patching and secure configuration practices to mitigate these persistent threats associated with AMI’s widely deployed infrastructure components.

CVE ID Title CVSS Severity Published
CVE-2026-33197 BDS Module Bypass Secure Boot Advisory — AptioV CWE-184 8.7 High 2026-09-08
CVE-2025-58770 TCG2 TPM RT Not Locked Issue — AptioV CWE-280 7.8AI High AI 2025-12-12
CVE-2025-33044 exFat Memory Corruption Issue — AptioV CWE-119 7.1AI High AI 2025-10-14
CVE-2025-22833 FixupArray Pointer Validation in NTFS — AptioV CWE-787 7.8AI High AI 2025-10-14
CVE-2025-22832 Buffer Overflow in NTFS when parsing the ATTRIBUTE_LIST — AptioV CWE-787 7.1AI High AI 2025-10-14
CVE-2025-22831 Buffer Overflow in NTFS when parsing the VOLUME_NAME — AptioV CWE-787 7.1AI High AI 2025-10-14
CVE-2025-33045 Legacy Serial Redirection SMRAM Vulnerabilities — AptioV CWE-123 8.2 High 2025-09-09
CVE-2025-22830 SmiFlash Race Condition Vulnerability — AptioV CWE-362 7.0AI High AI 2025-08-12
CVE-2025-22834 ThirdPartyVideo SetVariable Vulnerability — AptioV CWE-665 4.2 Medium 2025-08-12
CVE-2025-33043 SMM buffer Integrity — AptioV CWE-20 5.8 Medium 2025-05-29
CVE-2024-42446 TOCTOU in SmmWhea — AptioV CWE-367 7.5 High 2025-05-13
CVE-2024-54084 SMM Arbitrary Write via TOCTOU Vulnerability — AptioV CWE-367 7.5 High 2025-03-11
CVE-2024-54085 Redfish Authentication Bypass — MegaRAC-SPx CWE-290 9.4 - 2025-03-11
CVE-2024-33659 BiosGuard Buffer Overflow and TOCTOU Vulnerability — AptioV CWE-20 7.8 - 2025-02-11
CVE-2024-42444 TOCTOU Race Condition between DMA and SMM — AptioV CWE-367 7.5 High 2025-01-14
CVE-2024-2315 SMM arbitrary code execution in Overclock — AptioV CWE-284 5.5AI Medium AI 2024-11-12
CVE-2024-33658 Buffer Overflow Vulnerability In OFBD — AptioV CWE-119 6.7AI Medium AI 2024-11-12
CVE-2024-33660 Potential Firmware update without integrity check — AptioV CWE-494 6.1AI Medium AI 2024-11-12
CVE-2024-42442 Runtime Service Access outside SMRAM — AptioV CWE-119 7.2 High 2024-11-12
CVE-2024-33657 Smm Callout in SmmComputrace Module — AptioV CWE-20 7.8 High 2024-08-21
CVE-2024-33656 Memory Leak in SmmComuptrace Module — AptioV CWE-269 7.8 High 2024-08-21
CVE-2023-37297 heap memory overflow — MegaRAC_SPx CWE-122 8.3 High 2024-01-09
CVE-2023-37296 Stack-based Buffer Overflow — MegaRAC_SPx CWE-121 8.3 High 2024-01-09
CVE-2023-37295 Heap-based Buffer Overflow — MegaRAC_SPx CWE-122 8.3 High 2024-01-09
CVE-2023-37294 Heap-based Buffer Overflow — MegaRAC_SPx CWE-122 8.3 High 2024-01-09
CVE-2023-37293 stack-based buffer overflow — MegaRAC_SPx CWE-121 9.6 Critical 2024-01-09
CVE-2023-34333 Untrusted Pointer Dereference — MegaRAC_SPx CWE-822 7.8 High 2024-01-09
CVE-2023-3043 Stack-based Buffer Overflow BMC — MegaRAC_SPx CWE-121 9.6 Critical 2024-01-09
CVE-2023-34332 Untrusted Pointer Dereference in BMC — MegaRAC_SPx CWE-822 7.8 High 2024-01-09
CVE-2023-39538 Failure when uploading a Logo image file — AptioV CWE-20 7.5 High 2023-12-06

This page lists every published CVE security advisory associated with AMI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.