Buffer Overflow Vulnerability in NVIDIA DGX-1 AMI SBIOS
CVE-2023-25506
7.5HIGH
What is CVE-2023-25506?
NVIDIA DGX-1 contains a vulnerability in the Ofbd component of AMI SBIOS, where improper handling of a preconditioned heap allows a user with elevated privileges to access memory beyond the allocated buffer. This can result in various security issues including unauthorized code execution, escalation of privileges, potential denial of service, and information disclosure. The ramifications may affect not only the DGX-1 system but can also extend to other connected components.
Affected Version(s)
NVIDIA DGX servers All SBIOS prior to S2W_3A13