Code injection via Dynamic Redfish Extension interface
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in AMI SPx's BMC allows attackers to inject and execute malicious code through the Dynamic Redfish Extension interface, potentially compromising the security of the entire system.
Technical detail
CWE-94 code injection vulnerability in AMI SPx BMC's Dynamic Redfish Extension interface permits unauthenticated or low-privileged users to inject arbitrary code that achieves remote execution. Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the affected BMC and potentially the managed system.
Summary generated and translated by AI from the official description.
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H