High severity7.5NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026
CVE-2022-42277
CVE-2022-42277
Description
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Affected products
3- cpe:2.3:o:nvidia:dgx_station_a100_firmware:*:*:*:*:sbios:*:*:*Range: <10.16
- Range: All SBIOS firmware versions prior to 10.16
Patches
Vulnerability mechanics
References
1- nvidia.custhelp.com/app/answers/detail/a_id/5435nvdVendor Advisory
News mentions
0No linked articles in our index yet.