Privilege Escalation in DGX A100 SBIOS by NVIDIA
CVE-2022-42285
6MEDIUM
Summary
The DGX A100 SBIOS from NVIDIA is impacted by a vulnerability in the Pre-EFI Initialization (PEI) phase. This issue allows a privileged user to disable SPI flash protection, potentially leading to severe consequences such as denial of service, escalation of privileges, or even data tampering on the affected systems.
Affected Version(s)
NVIDIA DGX servers All SBIOS firmware versions prior to 1.18
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved