CVE Published: 12/06/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: AMI |
Vendor: AMI |
Product: MegaRAC_SPx Status : PUBLISHED
CVE-2023-34342 Description
AMI BMC contains a vulnerability in the IPMI handler, where an
attacker can upload and download arbitrary files under certain circumstances,
which may lead to denial of service, escalation of privileges, information
disclosure, or data tampering.
Metrics
CVSS Version: 3.1 |
Base Score: 6 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* LOW Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* UNCHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-22 CWE Name: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (
Path Traversal
) Source: AMI
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC Description: Denial of Service, Escalation of Privileges, Information Disclosure, Data Tampering