Database/Firmware, BMC & network fabric

AMI MegaRAC: Default credentials — Redfish API accessible with shipped account
CVSS 8.3CVE-2022-40259Firmware, BMC & network fabriccurated
Impact
Default credentials — Redfish API accessible with shipped account; full BMC control
Who can reach it
Network / Redfish API
What to do
Credential rotation at rack intake; treat any node received from an ODM as compromised-by-default until BMC accounts are reset
References
Related entries
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCCVE-2022-40242 · AMI MegaRACHigh
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- Lenovo XClarity Controller (XCC) - API privilege escalation: A read-only XCC user gains elevated privileges throughCVE-2023-0683 · Lenovo XClarity Controller (XCC) - API privilege escalationHigh
- HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting): Cross-site scripting in the iLO web interface across all threeCVE-2023-28083 · HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.