GPU VulnDB

Database/Firmware, BMC & network fabric

AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC account

CVE-2022-26872Firmware, BMC & network fabriccurated

Impact

Password reset interception via the API — attacker takes over an admin BMC account

Who can reach it

Network / BMC API

What to do

BMC firmware update; interim mitigation is disabling the self-service password reset flow

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.