Vulnerabilities > Nvidia > DGX A100 Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-04 | CVE-2023-25522 | Improper Input Validation vulnerability in Nvidia DGX A100 Firmware and DGX A800 Firmware NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuration information in an unexpected format. | 7.8 |
2023-04-22 | CVE-2023-0202 | Unspecified vulnerability in Nvidia DGX A100 Firmware 1.8 NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacySmmSredir SMM APIs. | 7.8 |
2023-04-22 | CVE-2023-0206 | Unspecified vulnerability in Nvidia DGX A100 Firmware 1.8 NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. | 7.8 |
2023-01-13 | CVE-2022-42288 | Information Exposure Through Discrepancy vulnerability in Nvidia DGX A100 Firmware NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure. | 5.3 |
2023-01-13 | CVE-2022-42289 | OS Command Injection vulnerability in Nvidia DGX A100 Firmware NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering. | 8.8 |
2023-01-13 | CVE-2022-42290 | OS Command Injection vulnerability in Nvidia DGX A100 Firmware NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering. | 8.8 |
2023-01-13 | CVE-2022-42276 | Missing Authentication for Critical Function vulnerability in Nvidia DGX A100 Firmware 1.8 NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. | 8.2 |
2023-01-13 | CVE-2022-42279 | OS Command Injection vulnerability in Nvidia DGX A100 Firmware NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering. | 8.8 |
2023-01-13 | CVE-2022-42281 | Out-of-bounds Write vulnerability in Nvidia DGX A100 Firmware 1.8 NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure. | 6.7 |
2023-01-12 | CVE-2022-42272 | Classic Buffer Overflow vulnerability in Nvidia DGX A100 Firmware NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may lead to code execution, denial of service or escalation of privileges. | 8.8 |