CVE
CVE-2023-31034

7.8HIGH

Key Information:

Vendor
nvidia
Status
Vendor
CVE Published:
12 January 2024

Summary

The NVIDIA DGX A100 SBIOS has been identified with a vulnerability that allows local attackers to bypass critical input validation checks via an integer overflow. This flaw can be exploited to cause a denial of service, enabling disruptive activities that hinder system performance. Furthermore, the successful exploitation of this vulnerability could lead to unauthorized information disclosure and data tampering, raising significant concerns for users relying on the system's integrity and availability.

Affected Version(s)

DGX A100 All SBOIS versions prior to 1.25

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.