CVE-2023-37293 is a stack-based buffer overflow vulnerability in AMI's MegaRAC SP-X Baseboard Management Controller (BMC) firmware. An attacker on an adjacent network can exploit this vulnerability without authentication, leading to a complete loss of confidentiality, integrity, and availability of the affected system. With a CVSS score of 8.8 (High), this vulnerability poses a significant risk. Currently, there is no public exploit code available, and it has not been observed in active exploitation, nor has it garnered significant community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12, < 12.7CPE matchmatch criteria | cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | ||
>= 13, < 13.6CPE matchmatch criteria | cpe:2.3:o:ami:megarac_sp-x:*:*:*:*:*:*:*:* | ||
>= 12, < 12.7CPE match | cpe:2.3:a:ami:megarac_spx:*:*:*:*:*:*:*:* | ||
>= 13, < 13.6CPE match | cpe:2.3:a:ami:megarac_spx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.