VYPR
High severity7.1NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026

CVE-2022-42280

CVE-2022-42280

Description

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

Affected products

3
  • Nvidia/BMC2 versions
    cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*range: <00.19.07
    • (no CPE)
  • Range: All BMC firmware versions prior to 00.19.07

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.