Database/Firmware, BMC & network fabric

AMI MegaRAC SPX (Redfish): User enumeration through Redfish
CVE-2023-25192Firmware, BMC & network fabriccurated
Impact
User enumeration through Redfish — maps valid BMC accounts fleet-wide ahead of a credential attack
Who can reach it
Network / Redfish, unauthenticated
What to do
BMC firmware update to SPx12-update-7.00 / SPx13-update-5.00; low severity alone, but it is the reconnaissance leg of the MegaRAC chain
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.