CVE-2022-2827
AMI MegaRAC User Enumeration Vulnerability
In short
AMI MegaRAC allows attackers to discover valid usernames on the system through an enumeration vulnerability. This matters because it reduces the effort needed to launch targeted attacks, making the system easier to compromise.
Technical detail
A user enumeration flaw in AMI MegaRAC permits unauthenticated attackers to enumerate valid user accounts through differential response analysis. This information disclosure (CWE-200) lowers the attack surface complexity for subsequent credential-based attacks against known accounts.
Summary generated and translated by AI from the official description.
AMI MegaRAC User Enumeration Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →