cbcvebase.

Nvidia Dgx Servers vulnerabilities

40 known vulnerabilities affecting nvidia/nvidia_dgx_servers.

Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH29MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2022-42277P3HIGHCVSS 8.2vAll SBIOS firmware versions prior to 10.162023-01-13
CVE-2022-42277 [HIGH] CWE-288 CVE-2022-42277: NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevat NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
nvd
CVE-2022-42276P3HIGHCVSS 8.2vAll SBIOS firmware versions prior to 1.182023-01-13
CVE-2022-42276 [HIGH] CWE-288 CVE-2022-42276: NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
nvd
CVE-2023-25506P3HIGHCVSS 8.2vAll SBIOS prior to S2W_3A132023-04-22
CVE-2023-25506 [HIGH] CWE-788 CVE-2023-25506: NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other compo
nvd
CVE-2023-25509P3HIGHCVSS 7.8vAll SBIOS prior to S2W_3A132023-04-22
CVE-2023-25509 [HIGH] CWE-119 CVE-2023-25509: NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of serv NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.
nvd
CVE-2022-42285P3HIGHCVSS 7.8vAll SBIOS firmware versions prior to 1.182023-01-13
CVE-2022-42285 [HIGH] CWE-1231 CVE-2022-42285: DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.
nvd
CVE-2023-25505P3HIGHCVSS 7.8vAll BMC versions prior to 3.39.32023-04-22
CVE-2023-25505 [HIGH] CWE-120 CVE-2023-25505: NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an atta NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authorization can cause a buffer overflow, which may lead to denial of service, information disclosure, or arbitrary code execution.
nvd
CVE-2022-42286P3HIGHCVSS 7.8vAll SBIOS firmware versions prior to 1.182023-01-13
CVE-2022-42286 [HIGH] CWE-119 CVE-2022-42286: DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.
nvd
CVE-2022-42274P3HIGHCVSS 7.8vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42274 [HIGH] CWE-120 CVE-2022-42274: NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.
nvd
CVE-2022-42271P3HIGHCVSS 7.8vAll BMC firmware versions prior to 00.19.072023-01-11
CVE-2022-42271 [HIGH] CWE-120 CVE-2022-42271: NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution
nvd
CVE-2022-42283P4HIGHCVSS 7.8vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42283 [HIGH] CWE-120 CVE-2022-42283: NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.
nvd
CVE-2022-42275P4HIGHCVSS 7.1vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42275 [HIGH] CWE-288 CVE-2022-42275: NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secure NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
nvd
CVE-2022-42282P4MEDIUMCVSS 5.5vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42282 [MEDIUM] CWE-22 CVE-2022-42282: NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitra NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.
nvd
CVE-2020-11488P4MEDIUMCVSS 6.7vAll DGX-1 with BMC firmware versions prior to 3.38.30, and all DGX-2 with BMC firmware versions prior to 1.06.062020-10-29
CVE-2020-11488 [MEDIUM] CWE-347 CVE-2020-11488: NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC fir NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.
nvd
CVE-2023-0201P4MEDIUMCVSS 6.7vAll BMC versions prior to 1.08.002023-04-22
CVE-2023-0201 [MEDIUM] CWE-118 CVE-2023-0201: NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a wr NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.
nvd
CVE-2023-0200P4MEDIUMCVSS 6.7vAll BMC versions prior to 1.08.002023-04-22
CVE-2023-0200 [MEDIUM] CWE-788 CVE-2023-0200: NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditione NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.
nvd
CVE-2022-42281P4MEDIUMCVSS 6.7vAll SBIOS firmware versions prior to 1.182023-01-13
CVE-2022-42281 [MEDIUM] CWE-787 CVE-2022-42281: NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privil NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.
nvd
CVE-2022-42284P4MEDIUMCVSS 5.5vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42284 [MEDIUM] CWE-312 CVE-2022-42284: NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This ma NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.
nvd
CVE-2022-42288P4MEDIUMCVSS 5.3vAll BMC firmware versions prior to 00.19.072023-01-13
CVE-2022-42288 [MEDIUM] CWE-208 CVE-2022-42288: NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
nvd
CVE-2020-11484P4MEDIUMCVSS 4.9vAll DGX-1 with BMC firmware versions prior to 3.38.302020-10-29
CVE-2020-11484 [MEDIUM] CVE-2020-11484: NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of the BMC/IPMI user password, which may lead to information disclosure.
nvd
CVE-2023-0207P4MEDIUMCVSS 4.4vAll SBIOS versions prior to 0.332023-04-22
CVE-2023-0207 [MEDIUM] CWE-732 CVE-2023-0207: NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM varia NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
nvd
Nvidia Dgx Servers vulnerabilities | cvebase