AMI develops firmware and management platforms for server and embedded systems, with a vulnerability footprint concentrated in its Aptio firmware and MegaRAC baseboard-management controller product lines that are deeply embedded in enterprise and data-center hardware. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged firmware context and the difficulty of patching deployed hardware. The exposure recurs through memory-safety and input-validation weakness classes including out-of-bounds writes, buffer overflows, and improper bounds checking, consistent with low-level firmware code written in C and exposed to network input through management interfaces. Defenders should prioritize inventory and updates for affected server platforms, particularly those with internet-exposed management networks, since remediation typically requires coordinated hardware vendor support. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by AMI over time
Of all the CVEs published by AMI as a CNA, 100.0% affect products that AMI develops as a vendor.
Of all the CVEs published that affect products developed by AMI, 80.6% are self-published by AMI as a CNA.
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-54085CRITICAL AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerabili | Mar 11, 2025 | 9.8 | 92 | YES | NO |
CVE-2022-40242CRITICAL MegaRAC Default Credentials Vulnerability | Dec 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40259CRITICAL MegaRAC Default Credentials Vulnerability | Dec 5, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-28863CRITICAL AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity. | Apr 18, 2023 | 9.1 | 28 | NO | NO |
CVE-2022-40250HIGH An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than oper | Sep 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-58770HIGH APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulner | Dec 12, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-34330HIGH AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerabili | Jul 18, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-34338CRITICAL AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerabilit | Jul 5, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-34335CRITICAL AMI BMC contains a vulnerability in the IPMI handler, where an
unauthenticated host is allowed to write to a host SPI flash, bypassing secure
boot protections. An exploitation of t | Jun 12, 2023 | 9.1 | 27 | NO | NO |
CVE-2025-22832HIGH APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l | Oct 14, 2025 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by AMI.
Media articles that mention a CVE ID that affects a product developed by AMI — matched by CVE ID, not by vendor name.