Out-of-bounds Write Vulnerability in NVIDIA DGX A100 SBIOS
CVE-2022-42281
6.7MEDIUM
What is CVE-2022-42281?
The NVIDIA DGX A100 has a reported vulnerability in its SBIOS related to the FsRecovery process. This issue could be exploited by a highly privileged local attacker, potentially resulting in an out-of-bounds write. Such an exploit may lead to serious consequences, including unauthorized code execution, denial of service, potential compromise of data integrity, and exposure of sensitive information.
Affected Version(s)
NVIDIA DGX servers All SBIOS firmware versions prior to 1.18