CVE-2022-40258 is a medium-severity vulnerability affecting AMI MegaRAC SP-X firmware versions 12 and 13, stemming from weak password hashes used for Redfish and API authentication. This allows unauthenticated attackers to remotely access sensitive information due to the low attack complexity. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant media attention and community discussion, indicating potential future interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.00CPE matchmatch criteria | cpe:2.3:o:ami:megarac_spx-12:*:*:*:*:*:*:*:* | ||
< 5.00CPE matchmatch criteria | cpe:2.3:o:ami:megarac_spx-13:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.