CVE-2022-31599: High severity nvidia dgx station a100 firmware vulnerability
Published Jul 4, 2022
·Updated
NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause access to an uninitialized pointer, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Affected Software
2 affected components
Nvidia Dgx A100 Firmware<22.5.5
Nvidia DGX A100
Event History
Jul 4, 2022
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA DGX A100 vulnerability?
The vulnerability ID for this NVIDIA DGX A100 vulnerability is CVE-2022-31599.
2
What is the severity rating of CVE-2022-31599?
CVE-2022-31599 has a severity rating of 8.2 (high).
3
What is the affected software for CVE-2022-31599?
The affected software for CVE-2022-31599 is NVIDIA DGX A100 Firmware version up to and excluding 22.5.5.
4
What is the impact of CVE-2022-31599?
CVE-2022-31599 may lead to code execution, escalation of privileges, denial of service, and information disclosure.
5
Is NVIDIA DGX A100 vulnerable to CVE-2022-31599?
No, NVIDIA DGX A100 is not vulnerable to CVE-2022-31599.