PublicCVE

CVE-2023-31033

MEDIUM6.8Auth bypass

Description

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS breakdown

CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected products

  • NVIDIA / DGX A100All BMC versions prior to 00.22.05 – All BMC versions prior to 00.22.05