CVE-2022-26872: high-severity vulnerability in AMI MegaRAC SPx-12
Password reset interception via API
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in AMI Megarac's API allows attackers to intercept password reset requests, potentially gaining unauthorized access to accounts. This happens because the API doesn't properly secure the password reset process, making it vulnerable to interception attacks.
The API endpoint handling password reset operations in AMI Megarac fails to implement adequate protection against request interception, allowing an attacker to capture or manipulate password reset tokens or credentials in transit. This vulnerability requires network-level access or a man-in-the-middle position to exploit, and successful exploitation results in account takeover.
In the same product, most dangerous first.