First published: Thu Oct 29 2020(Updated: )
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong, which may lead to information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Bmc Firmware | <3.38.30 | |
NVIDIA DGX-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-11616.
The severity of CVE-2020-11616 is high with a value of 7.5.
The affected software is Intel BMC Firmware versions prior to 3.38.30 and NVIDIA DGX-1 servers.
CVE-2020-11616 may lead to information disclosure due to a weak PRNG algorithm in the AMI BMC firmware.
To fix CVE-2020-11616, update the BMC firmware to version 3.38.30 or later.