First published: Thu Oct 29 2020(Updated: )
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Bmc Firmware | <3.38.30 | |
NVIDIA DGX-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11615.
The severity of CVE-2020-11615 is high with a severity value of 7.5.
NVIDIA DGX servers with all BMC firmware versions prior to 3.38.30 are affected by CVE-2020-11615.
The impact of CVE-2020-11615 is possible information disclosure.
To fix CVE-2020-11615, update the BMC firmware to version 3.38.30 or later.