CVE-2022-42276: High severity nvidia dgx station a100 firmware vulnerability
Published Jan 13, 2023
·Updated
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Affected Software
2 affected components
Nvidia Dgx A100 Firmware<1.18
Nvidia DGX A100
Event History
Jan 13, 2023
CVE Published
via MITRE·01:32 AM
Data Sourced
via MITRE·01:32 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-42276.
2
What is the severity of CVE-2022-42276?
The severity of CVE-2022-42276 is high with a severity value of 8.2.
3
What is the affected software?
The affected software is NVIDIA DGX A100 Firmware.
4
What are the potential impacts of CVE-2022-42276?
The potential impacts of CVE-2022-42276 include code execution, escalation of privileges, denial of service, and information disclosure.
5
Is NVIDIA DGX A100 vulnerable to CVE-2022-42276?
No, NVIDIA DGX A100 is not vulnerable to CVE-2022-42276.
6
How can I fix CVE-2022-42276?
To fix CVE-2022-42276, it is recommended to apply the latest firmware update provided by NVIDIA.