Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (Redfish): Password disclosure through Redfish
CVE-2023-25191Firmware, BMC & network fabriccurated
Impact
Password disclosure through Redfish; credentials frequently reused across a whole fleet of identically-provisioned nodes
Who can reach it
Network / Redfish
What to do
Firmware update to SPx_12-update-7.00 / SPx_13-update-5.00 plus a fleet-wide BMC credential rotation
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.