CVE-2022-26872 – Password reset interception via API
https://notcve.org/view.php?id=CVE-2022-26872
AMI Megarac Password reset interception via API • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023001.pdf https://security.netapp.com/advisory/ntap-20230731-0008 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2022-2827 – AMI MegaRAC User Enumeration Vulnerability
https://notcve.org/view.php?id=CVE-2022-2827
AMI MegaRAC User Enumeration Vulnerability Vulnerabilidad de enumeración de usuarios de AMI MegaRAC • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023001.pdf • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-40259 – MegaRAC Default Credentials Vulnerability
https://notcve.org/view.php?id=CVE-2022-40259
MegaRAC Default Credentials Vulnerability Vulnerabilidad de credenciales predeterminadas de MegaRAC • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023001.pdf • CWE-287: Improper Authentication CWE-798: Use of Hard-coded Credentials •
CVE-2022-40242 – MegaRAC Default Credentials Vulnerability
https://notcve.org/view.php?id=CVE-2022-40242
MegaRAC Default Credentials Vulnerability Vulnerabilidad de credenciales predeterminadas de MegaRAC • https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023001.pdf • CWE-287: Improper Authentication CWE-798: Use of Hard-coded Credentials •