User Enumeration Vulnerability in AMI MegaRAC SPX Devices
CVE-2023-25192
5.3MEDIUM
What is CVE-2023-25192?
The AMI MegaRAC SPX devices exhibit a vulnerability that enables attackers to perform User Enumeration through the Redfish management interface. This flaw can be exploited to gather insights about user accounts, potentially aiding in further attacks. Users are encouraged to upgrade to SPx12-update-7.00 or SPx13-update-5.00 to address this issue and enhance their device security.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved