← back
CVE-2022-40258mediumCWE-916

Weak password hashes for Redfish & API

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
In short

AMI Megarac uses weak password hashing methods for its Redfish and API interfaces, making stored passwords vulnerable to being cracked if an attacker gains access to the password database. This is important because weak hashes can be quickly broken, allowing attackers to compromise user accounts.

Technical detail

The vulnerability stems from the use of insufficient cryptographic hashing algorithms (CWE-916) for password storage in AMI Megarac's Redfish and API implementations. If an attacker obtains the password hash database through other means (e.g., access to configuration files or database), weak hashes can be rapidly reversed via dictionary or brute-force attacks, leading to account compromise and potential escalation of privileges within the management interface.

Summary generated and translated by AI from the official description.
AMI Megarac Weak password hashes for Redfish & API
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N