Password reset interception via API
CVE-2022-26872

8.3HIGH

Key Information:

Vendor

Ami

Vendor
CVE Published:
30 January 2023

What is CVE-2022-26872?

The AMI Megarac platform is exposed to a significant security vulnerability that allows attackers to intercept API calls related to password resets. This flaw can enable unauthorized access to user accounts, compromising sensitive information and system integrity. It is crucial for organizations using AMI Megarac to implement the recommended security patches and safeguard their systems against potential exploitation. For detailed mitigation strategies, refer to the security advisories linked.

Affected Version(s)

MegaRAC SPx-12 0

MegaRAC SPx-13 0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlad Bakin from Eclypsium Research
.