← back
CVE-2022-40242

MegaRAC Default Credentials Vulnerability

CVSS 7.5 HIGHEPSS 0.7%CWE-798
In short

MegaRAC devices come with built-in usernames and passwords that are publicly known, allowing attackers to gain unauthorized access to system management interfaces. This is critical because anyone with internet access can potentially take control of these devices.

Technical detail

The vulnerability stems from hardcoded default credentials in MegaRAC BMC firmware (CWE-798). An unauthenticated attacker can access the web interface or IPMI services using known default credentials, bypassing authentication controls and gaining administrative privileges with no additional prerequisites.

Summary generated and translated by AI from the official description.
MegaRAC Default Credentials Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →