Access Violation Vulnerability in NVIDIA DGX-2
CVE-2023-0200
7.5HIGH
Summary
The NVIDIA DGX-2 is susceptible to an access violation vulnerability in the OFBD component. A user with elevated privileges can manipulate a specially crafted heap, leading to a potential buffer overflow. This scenario may enable unauthorized code execution, privilege escalation, denial of service, and information disclosure. Organizations using the DGX-2 should assess their systems and implement the necessary security patches to mitigate potential risks.
Affected Version(s)
NVIDIA DGX servers All BMC versions prior to 1.08.00
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved