First published: Thu Oct 29 2020(Updated: )
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Bmc Firmware | <3.38.30 | |
NVIDIA DGX-1 | ||
Intel Bmc Firmware | <1.06.06 | |
NVIDIA DGX-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11489 is a vulnerability in the AMI BMC firmware used in NVIDIA DGX servers, specifically affecting all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06.
CVE-2020-11489 may lead to information disclosure as default SNMP community strings are used in the vulnerable AMI BMC firmware.
CVE-2020-11489 affects all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06.
CVE-2020-11489 has a severity rating of 7.5 (high).
To mitigate CVE-2020-11489, it is recommended to update the BMC firmware to version 3.38.30 or later for DGX-1, and version 1.06.06 or later for DGX-2.