Local Code Execution and Information Disclosure Vulnerability in NVIDIA DGX A100
CVE-2022-31599
8.2HIGH
What is CVE-2022-31599?
NVIDIA DGX A100 is affected by a vulnerability in the System BIOS (SBIOS) related to the Open Firmware Device Tree (Ofbd). This issue allows a local user with elevated privileges to manipulate an uninitialized pointer, potentially leading to unauthorized code execution, privilege escalation, denial of service, and exposure of sensitive information. The impact may extend to other components of the system, thereby amplifying the risk to overall system integrity.
Affected Version(s)
NVIDIA DGX A100 Versions prior to 22.5.5