Database/Firmware, BMC & network fabric

AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attack
CVSS 7.5CVE-2022-2827Firmware, BMC & network fabriccurated
Impact
User enumeration — lets an attacker map valid BMC accounts before credential attack
Who can reach it
Network
What to do
BMC firmware update; low individual severity but it is the reconnaissance step for the rest of the MegaRAC chain
References
Related entries
- AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCCVE-2022-40242 · AMI MegaRACHigh
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountCVE-2022-40259 · AMI MegaRACHigh
- Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferCVE-2022-30283 · Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU)High
- OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundCVE-2022-3409 · OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.