A vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username
CVE-2023-34344

5.3MEDIUM

Key Information:

Vendor

AMI

Vendor
CVE Published:
12 June 2023

What is CVE-2023-34344?

AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.

Affected Version(s)

MegaRAC_SPx ARM 12.0 < 12.7

MegaRAC_SPx ARM 13.0 < 13.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NVIDIA Offensive Security Research (OSR) team
.