AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.
https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023006.pdf
https://www.bleepingcomputer.com/news/security/cisa-ami-megarac-bug-that-lets-hackers-brick-servers-now-actively-exploited/
https://www.securityweek.com/critical-ami-bmc-vulnerability-exposes-servers-to-disruption-takeover/
https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bug-can-let-attackers-hijack-brick-servers/
https://thehackernews.com/2025/03/new-critical-ami-bmc-vulnerability.html
https://security.netapp.com/advisory/ntap-20230814-0004/
Source: Mitre, NVD
Published: 2023-07-18
Updated: 2025-02-13
Named Vulnerability: BMC&C
Base Score: 7.7
Vector: CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8
Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00295