Improper Validation Vulnerability in NVIDIA DGX A100 SBIOS
CVE-2022-31603
6.4MEDIUM
Summary
The NVIDIA DGX A100 has a vulnerability within its SBIOS component, specifically affecting the IpSecDxe module. This flaw allows users with elevated privileges to exploit improper validation of an array index. Exploitation of this vulnerability could lead to code execution scenarios, resulting in potential denial of service, risks to data integrity, and unauthorized information disclosure. Organizations utilizing the DGX A100 should be aware of these risks and ensure appropriate security measures are in place. For further information, refer to NVIDIA's support documentation.
Affected Version(s)
NVIDIA DGX A100 Versions prior to 22.5.5
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved