Unrated severityNVD Advisory· Published Sep 20, 2023· Updated Aug 2, 2024
CVE-2023-25529
CVE-2023-25529
Description
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.
Affected products
2All BMC versions prior to 00.22.05+ 1 more
- (no CPE)range: All BMC versions prior to 00.22.05
- (no CPE)range: All versions prior to 23.08.07
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.