Buffer Overflow Vulnerability in NVIDIA DGX-1 AMI SBIOS
CVE-2023-25506

7.5HIGH

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
22 April 2023

Summary

NVIDIA DGX-1 contains a vulnerability in the Ofbd component of AMI SBIOS, where improper handling of a preconditioned heap allows a user with elevated privileges to access memory beyond the allocated buffer. This can result in various security issues including unauthorized code execution, escalation of privileges, potential denial of service, and information disclosure. The ramifications may affect not only the DGX-1 system but can also extend to other connected components.

Affected Version(s)

NVIDIA DGX servers All SBIOS prior to S2W_3A13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.