Local Code Execution and Information Disclosure Vulnerability in NVIDIA DGX A100
CVE-2022-31599
8.2HIGH
Summary
NVIDIA DGX A100 is affected by a vulnerability in the System BIOS (SBIOS) related to the Open Firmware Device Tree (Ofbd). This issue allows a local user with elevated privileges to manipulate an uninitialized pointer, potentially leading to unauthorized code execution, privilege escalation, denial of service, and exposure of sensitive information. The impact may extend to other components of the system, thereby amplifying the risk to overall system integrity.
Affected Version(s)
NVIDIA DGX A100 Versions prior to 22.5.5
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved