← back
CVE-2023-34343highCWE-78

CVE-2023-34343

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.8%
exploitation probability
0.8%top 44% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in AMI BMC's REST API allows someone with access to inject harmful commands that can execute code, crash the system, expose data, or modify files.

Technical detail

CWE-78 command injection vulnerability in SPX REST API allows authenticated/privileged attackers to inject arbitrary shell commands leading to code execution, DoS, information disclosure, and data integrity compromise.

Summary generated and translated by AI from the official description.
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
AMI · MegaRAC_SPx