CVE-2020-11489: High severity intel bmc firmware vulnerability
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11489?
CVE-2020-11489 is a vulnerability in the AMI BMC firmware used in NVIDIA DGX servers, specifically affecting all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06.
How does CVE-2020-11489 impact NVIDIA DGX servers?
CVE-2020-11489 may lead to information disclosure as default SNMP community strings are used in the vulnerable AMI BMC firmware.
Which versions of BMC firmware are affected by CVE-2020-11489?
CVE-2020-11489 affects all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06.
What is the severity of CVE-2020-11489?
CVE-2020-11489 has a severity rating of 7.5 (high).
How can I mitigate CVE-2020-11489?
To mitigate CVE-2020-11489, it is recommended to update the BMC firmware to version 3.38.30 or later for DGX-1, and version 1.06.06 or later for DGX-2.