Skip to main content

Vendor/product archive

nvidia / bmc CVEs

Beta · best-effort

13 CVEs tagged to nvidia / bmc0 Critical, 7 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2023-25508

Published Apr 22, 2023

NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download arbitrary files under certain…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25507

Published Apr 22, 2023

NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25505

Published Apr 22, 2023

NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authorization can cause a buffer overflow, w…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0201

Published Apr 22, 2023

NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code executio…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0200

Published Apr 22, 2023

NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code executi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42287

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42284

Published Jan 13, 2023

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42283

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42282

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42280

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42278

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42275

Published Jan 13, 2023

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42274

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1