Improper Validation Vulnerability in NVIDIA DGX A100 SBIOS
CVE-2022-31603

6.4MEDIUM

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
4 July 2022

Summary

The NVIDIA DGX A100 has a vulnerability within its SBIOS component, specifically affecting the IpSecDxe module. This flaw allows users with elevated privileges to exploit improper validation of an array index. Exploitation of this vulnerability could lead to code execution scenarios, resulting in potential denial of service, risks to data integrity, and unauthorized information disclosure. Organizations utilizing the DGX A100 should be aware of these risks and ensure appropriate security measures are in place. For further information, refer to NVIDIA's support documentation.

Affected Version(s)

NVIDIA DGX A100 Versions prior to 22.5.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.