CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ami

megarac_sp-x

30 known vulnerabilities · sorted by CVSS score

CVE-2024-54085
CRITICAL9.8

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+10
Network
Published Mar 11, 2025
Page 1 of 2
CVE-2023-37293
CRITICAL9.6

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2023-3043
CRITICAL9.6

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2023-28863
CRITICAL9.1

AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.

ami / megarac_sp-x+1
Network
Published Apr 18, 2023
CVE-2023-34329
CRITICAL9.1

AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.

ami / megarac_sp-x+1
Network
Published Jul 18, 2023
CVE-2023-37295
HIGH8.3

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2022-26872
HIGH8.3

AMI Megarac Password reset interception via API

ami / megarac_sp-x+1
Network
Published Jan 30, 2023
CVE-2023-37297
HIGH8.3

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2022-40259
HIGH8.3

MegaRAC Default Credentials Vulnerability

ami / megarac_sp-x+1
Network
Published Dec 5, 2022
CVE-2023-37294
HIGH8.3

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2023-37296
HIGH8.3

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Adjacent
Published Jan 9, 2024
CVE-2023-34330
HIGH8.2

AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

ami / megarac_sp-x+1
Local
Published Jul 18, 2023
CVE-2023-34336
HIGH8.1

AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may lead to code execution, denial of service, or escalation of privileges.  

ami / megarac_sp-x+1
Network
Published Jun 12, 2023
CVE-2023-34332
HIGH7.8

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Local
Published Jan 9, 2024
CVE-2023-34333
HIGH7.8

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

ami / megarac_sp-x+1
Local
Published Jan 9, 2024
CVE-2023-34337
HIGH7.6

AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

ami / megarac_sp-x+1
Adjacent
Published Jul 5, 2023
CVE-2022-40242
HIGH7.5

MegaRAC Default Credentials Vulnerability

ami / megarac_sp-x+1
Network
Published Dec 5, 2022
CVE-2022-2827
HIGH7.5

AMI MegaRAC User Enumeration Vulnerability

ami / megarac_sp-x+1
Network
Published Dec 5, 2022
CVE-2023-25191
HIGH7.5

AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.

ami / megarac_sp-x+1
Network
Published Feb 15, 2023
CVE-2023-34343
HIGH7.2

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering.

ami / megarac_sp-x+1
Network
Published Jun 12, 2023