CVE-2022-31602: Medium severity nvidia dgx station a100 firmware vulnerability
NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31602?
CVE-2022-31602 is a vulnerability found in the SBIOS in the IpSecDxe component of NVIDIA DGX A100.
How does the CVE-2022-31602 vulnerability occur?
The CVE-2022-31602 vulnerability occurs due to an out-of-bounds write vulnerability in the SBIOS IpSecDxe component of NVIDIA DGX A100.
What are the potential impacts of CVE-2022-31602?
The potential impacts of CVE-2022-31602 include code execution, denial of service, data integrity impact, and information disclosure.
Is NVIDIA DGX A100 firmware affected by CVE-2022-31602?
Yes, NVIDIA DGX A100 firmware versions up to and excluding 22.5.5 are affected by CVE-2022-31602.
How can I protect myself from CVE-2022-31602?
To protect yourself from CVE-2022-31602, update your NVIDIA DGX A100 firmware to version 22.5.5 or later.