hard coded cryptographic key
CVE-2023-34338
7.1HIGH
What is CVE-2023-34338?
The AMI SPx system contains a significant vulnerability within its Baseboard Management Controller (BMC). An attacker can exploit this issue by leveraging a hard-coded cryptographic key embedded within a hard-coded certificate, which may compromise the confidentiality, integrity, and availability of the system. This risk emphasizes the urgent need for system administrators to review their security configurations and implement appropriate mitigation strategies to safeguard against potential exploitation.
Affected Version(s)
MegaRAC_SPx ARM 12.0 < 12.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved