CVE-2023-31034

CWE-190Integer Overflow3 documents3 sources
Severity
7.8HIGH
EPSS
0.0%
top 99.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12

Description

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:HExploitability: 0.8 | Impact: 5.3

Affected Packages2 packages

CVEListV5nvidia/dgx_a100All SBOIS versions prior to 1.25

🔴Vulnerability Details

2
CVEList
CVE2024-01-12
GHSA
GHSA-r2x9-77mc-c6x6: NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow2024-01-12
CVE-2023-31034 (HIGH CVSS 7.8) | NVIDIA DGX A100 SBIOS contains a vu | cvebase.io