Improper Input Validation in NVIDIA DGX H100 BMC REST Service
CVE-2023-31012
6.1MEDIUM
Summary
The NVIDIA DGX H100 BMC features a vulnerability in its REST service that allows an attacker to exploit improper input validation. This vulnerability can lead to unauthorized access, enabling potential privilege escalation and information disclosure. It highlights the importance of implementing robust input validation mechanisms to safeguard sensitive data and user privileges.
Affected Version(s)
DGX H100 BMC All versions prior to 23.08.07
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved