Code Execution and Privilege Escalation Vulnerability in NVIDIA DGX-1 SBIOS
CVE-2023-25509

6MEDIUM

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
22 April 2023

Summary

The NVIDIA DGX-1 SBIOS has a vulnerability in the Boot Device Selection (Bds) component that could allow an attacker to execute arbitrary code or cause a denial of service. This vulnerability also poses the risk of privilege escalation, enabling unauthorized access or control over the affected systems.

Affected Version(s)

NVIDIA DGX servers All SBIOS prior to S2W_3A13

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.