Skip to main content

Vendor/product archive

nvidia / dgx_a100 CVEs

Beta · best-effort

39 CVEs tagged to nvidia / dgx_a1003 Critical, 21 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2023-31035

Published Jan 12, 2024

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31034

Published Jan 12, 2024

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31033

Published Jan 12, 2024

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0206

Published Apr 22, 2023

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A successful exploit of this vulnerability ma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0202

Published Apr 22, 2023

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacySmmSredir SMM APIs. A successful explo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42290

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, informa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42289

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, informa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42287

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42285

Published Jan 13, 2023

DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, es…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42284

Published Jan 13, 2023

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42283

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42282

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42281

Published Jan 13, 2023

NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code exe…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42280

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42279

Published Jan 13, 2023

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, informa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2