Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

AMI

First CVE: Sep 20, 2022Active for: 4 yearsTotal CVEs: 62
64.8
VTI Score
TOP TARGET

AMI develops firmware and management platforms for server and embedded systems, with a vulnerability footprint concentrated in its Aptio firmware and MegaRAC baseboard-management controller product lines that are deeply embedded in enterprise and data-center hardware. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged firmware context and the difficulty of patching deployed hardware. The exposure recurs through memory-safety and input-validation weakness classes including out-of-bounds writes, buffer overflows, and improper bounds checking, consistent with low-level firmware code written in C and exposed to network input through management interfaces. Defenders should prioritize inventory and updates for affected server platforms, particularly those with internet-exposed management networks, since remediation typically requires coordinated hardware vendor support. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
62
Total CVEs
More Total CVEs than 99% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
1.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by AMI over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2022
3 years ago
Most Recent CVE
Dec 12, 2025
224 days ago

Self-Reporting Analysis

Of all the CVEs published by AMI as a CNA, 100.0% affect products that AMI develops as a vendor.

100.0%
Self-reported: 50 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by AMI, 80.6% are self-published by AMI as a CNA.

80.6%
19.4%
Self-published: 50 (80.6%)
Other CNAs: 12 (19.4%)

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (62 CVEs).

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-54085CRITICAL
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerabili
Mar 11, 20259.892YESNO
CVE-2022-40242CRITICAL
MegaRAC Default Credentials Vulnerability
Dec 5, 20229.830NONO
CVE-2022-40259CRITICAL
MegaRAC Default Credentials Vulnerability
Dec 5, 20229.829NONO
CVE-2023-28863CRITICAL
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Apr 18, 20239.128NONO
CVE-2022-40250HIGH
An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than oper
Sep 20, 20228.828NONO
CVE-2025-58770HIGH
APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulner
Dec 12, 20258.827NONO
CVE-2023-34330HIGH
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerabili
Jul 18, 20238.827NONO
CVE-2023-34338CRITICAL
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerabilit
Jul 5, 20239.827NONO
CVE-2023-34335CRITICAL
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections. An exploitation of t
Jun 12, 20239.127NONO
CVE-2025-22832HIGH
APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l
Oct 14, 20257.826NONO
View all 62 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products62 CVEs
18%
71%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local29 (46.8%)
Network24 (38.7%)
Unknown0 (0.0%)
Physical2 (3.2%)
Adjacent Network7 (11.3%)
Attack Complexity
Low58 (93.5%)
High4 (6.5%)
Unknown0 (0.0%)
User Interaction
None59 (95.2%)
Unknown0 (0.0%)
Required3 (4.8%)
Privileges Required
Low37 (59.7%)
High4 (6.5%)
None21 (33.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (62 CVEs).

CISA KEV
1 CVE
1.6% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by AMI.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by AMI — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For AMI's Products

View all 3 CNAs →

Top CWEs