First published: Fri Jan 13 2023(Updated: )
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA BMC | <00.19.07 | |
NVIDIA DGX A100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42274 is a vulnerability in NVIDIA BMC's IPMI handler that allows an authorized attacker to cause a buffer overflow and potentially execute arbitrary code or cause a denial of service.
CVE-2022-42274 has a severity rating of 7.8 (high).
CVE-2022-42274 affects NVIDIA BMC versions up to excluding 00.19.07.
An authorized attacker can exploit CVE-2022-42274 to cause a buffer overflow in NVIDIA BMC's IPMI handler, potentially leading to code execution or a denial of service.
NVIDIA DGX A100 is not vulnerable to CVE-2022-42274.
To fix CVE-2022-42274, it is recommended to apply the latest security patches and updates provided by NVIDIA.
You can find more information about CVE-2022-42274 in the NVIDIA security advisory: https://nvidia.custhelp.com/app/answers/detail/a_id/5435