CVE-2023-34336: AMI MegaRAC SPx

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may lead to code execution, denial of service, or escalation of privileges.  

Affected products

  • AMI MegaRAC SPx: from 12.0, before 12.7 (fixed in 12.7); from 13.0, before 13.5 (fixed in 13.5)

Published 2023-06-12. Last modified 2026-06-17.