VYPR

Dgx A100 Firmware

by Nvidia

CVEs (28)

  • CVE-2022-42281MedJan 13, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

  • CVE-2022-31601MedJul 4, 2022
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

  • CVE-2023-31034MedJan 12, 2024
    risk 0.43cvss 6.6epss 0.00

    NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

  • CVE-2023-31025MedJan 12, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2022-31603MedJul 4, 2022
    risk 0.42cvss 6.4epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and…

  • CVE-2022-31602MedJul 4, 2022
    risk 0.42cvss 6.4epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information…

  • CVE-2022-42288MedJan 13, 2023
    risk 0.34cvss 5.3epss 0.00

    NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.

  • CVE-2023-31031MedJan 12, 2024
    risk 0.27cvss 4.2epss 0.00

    NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

Page 2 of 2