CVE
CVE-2023-31034

6.6MEDIUM

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
12 January 2024

What is CVE-2023-31034?

The NVIDIA DGX A100 SBIOS has been identified with a vulnerability that allows local attackers to bypass critical input validation checks via an integer overflow. This flaw can be exploited to cause a denial of service, enabling disruptive activities that hinder system performance. Furthermore, the successful exploitation of this vulnerability could lead to unauthorized information disclosure and data tampering, raising significant concerns for users relying on the system's integrity and availability.

Affected Version(s)

DGX A100 All SBOIS versions prior to 1.25

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.