Password reset interception via API
CVE-2022-26872
8.3HIGH
What is CVE-2022-26872?
The AMI Megarac platform is exposed to a significant security vulnerability that allows attackers to intercept API calls related to password resets. This flaw can enable unauthorized access to user accounts, compromising sensitive information and system integrity. It is crucial for organizations using AMI Megarac to implement the recommended security patches and safeguard their systems against potential exploitation. For detailed mitigation strategies, refer to the security advisories linked.
Affected Version(s)
MegaRAC SPx-12 0
MegaRAC SPx-13 0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vlad Bakin from Eclypsium Research