Database/Firmware, BMC & network fabric

AMI MegaRAC: Weak MD5 password hashing for BMC accounts
CVSS 5.3CVE-2022-40258Firmware, BMC & network fabriccurated
Impact
Weak MD5 password hashing for BMC accounts; offline cracking of captured hashes
Who can reach it
Local/offline after hash disclosure
What to do
BMC firmware update plus credential rotation, since previously-hashed passwords must be considered recoverable
References
Related entries
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountCVE-2022-40259 · AMI MegaRACHigh
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCCVE-2022-40242 · AMI MegaRACHigh
- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableCVE-2023-20582 · AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checksMedium
- AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checks: The IOMMU mishandles certain special address rangesCVE-2023-20584 · AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checksMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.