First published: Fri Jan 13 2023(Updated: )
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA BMC | <00.19.07 | |
NVIDIA DGX A100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this NVIDIA BMC IPMI handler vulnerability is CVE-2022-42275.
This vulnerability allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections, which may lead to a loss of integrity and denial of service.
The NVIDIA BMC software version 00.19.07 is affected by this vulnerability.
There is currently no known fix or patch available for this vulnerability. It is recommended to follow the vendor's security advisory for any updates or mitigation steps.
You can find more information about this vulnerability on the NVIDIA customer support website: https://nvidia.custhelp.com/app/answers/detail/a_id/5435