Nvidia Dgx A100 vulnerabilities

9 known vulnerabilities affecting nvidia/dgx_a100.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-31029CRITICALCVSS 9.8vAll BMC versions prior to 00.22.052024-01-12
CVE-2023-31029 [CRITICAL] CWE-121 CVE-2023-31029: NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemo NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampe
cvelistv5nvd
CVE-2023-31030CRITICALCVSS 9.8vAll BMC versions prior to 00.22.052024-01-12
CVE-2023-31030 [CRITICAL] CWE-121 CVE-2023-31030: NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attack NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2023-31024CRITICALCVSS 9.8vAll BMC versions prior to 00.22.052024-01-12
CVE-2023-31024 [CRITICAL] CWE-121 CVE-2023-31024: NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attack NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2023-31033HIGHCVSS 8.0vAll BMC versions prior to 00.22.052024-01-12
CVE-2023-31033 [MEDIUM] CWE-306 CVE-2023-31033: NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue f NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2023-31031HIGHCVSS 7.8vAll SBOIS versions prior to 1.252024-01-12
CVE-2023-31031 [MEDIUM] CWE-122 CVE-2023-31031: NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2023-31035HIGHCVSS 7.8vAll SBOIS versions prior to 1.252024-01-12
CVE-2023-31035 [HIGH] CWE-20 CVE-2023-31035: NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerabil NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.
cvelistv5nvd
CVE-2023-31025HIGHCVSS 7.5vAll BMC versions prior to 00.22.052024-01-12
CVE-2023-31025 [MEDIUM] CWE-90 CVE-2023-31025: NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A s NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.
cvelistv5nvd
CVE-2023-31034HIGHCVSS 7.8vAll SBOIS versions prior to 1.252024-01-12
CVE-2023-31034 [MEDIUM] CWE-190 CVE-2023-31034: NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation che NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2023-31032MEDIUMCVSS 5.5vAll SBOIS versions prior to 1.252024-01-12
CVE-2023-31032 [HIGH] CWE-627 CVE-2023-31032: NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service.
cvelistv5nvd