AMI

First CVE: Jun 12, 2023Active for: 3 years
50
CVEs Published
More CVEs Published than 58% of tracked CNAs
16.7
Avg CVEs / Year
More Avg CVEs / Year than 64% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
2.0%
In CISA KEV
Higher KEV Rate than 91% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by AMI as a CNA, 100.0% affect products that AMI develops as a vendor.

100.0%
Self-reported: 50Third-party: 0

Of all the CVEs published that affect products developed by AMI, 80.6% are self-published by AMI as a CNA.

80.6%
19.4%
Self-published: 50Published by other CNAs: 12

Trends Over Time

The number and severity of CVEs published by AMI over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2023
3 years ago
Most Recent CVE
Dec 12, 2025
224 days ago

Top CVEs

All CVEs published by AMI as a CNA, regardless of affected vendor or product.

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabili
Mar 11, 20259.892YESNO
APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulner
Dec 12, 20258.827NONO
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerabili
Jul 18, 20238.827NONO
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerabilit
Jul 5, 20239.827NONO
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections. An exploitation of t
Jun 12, 20239.127NONO
APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l
Oct 14, 20257.826NONO
APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l
Oct 14, 20257.826NONO
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this
Jul 5, 20238.826NONO
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitati
Oct 14, 20257.825NONO
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead t
Jul 18, 20238.025NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA50 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local25 (50.0%)
Network16 (32.0%)
Unknown0 (0.0%)
Physical2 (4.0%)
Adjacent Network7 (14.0%)
Attack Complexity
Low46 (92.0%)
High4 (8.0%)
Unknown0 (0.0%)
User Interaction
None48 (96.0%)
Unknown0 (0.0%)
Required2 (4.0%)
Privileges Required
Low36 (72.0%)
High1 (2.0%)
None13 (26.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (50 CVEs).

CISA KEV
1 CVE
2.0% of CVEs· 91st percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by AMI as a CNA.

Media Mentions

Media articles that mention a CVE ID published by AMI as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs