CVE-2023-25529

8.1HIGH

Key Information

Vendor
NVIDIA
Status
DGX H100 BMC
DGX A100 BMC
Vendor
CVE Published:
20 September 2023

Summary

NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.

Affected Version(s)

DGX H100 BMC = All versions prior to 23.08.07

DGX A100 BMC = All BMC versions prior to 00.22.05

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.