Database/Firmware, BMC & network fabric

AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC account
CVE-2022-26872Firmware, BMC & network fabriccurated
Impact
Password reset interception via the API — attacker takes over an admin BMC account
Who can reach it
Network / BMC API
What to do
BMC firmware update; interim mitigation is disabling the self-service password reset flow
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.