First published: Fri Jan 13 2023(Updated: )
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Dgx A100 Firmware | <1.18 | |
NVIDIA DGX A100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42276.
The severity of CVE-2022-42276 is high with a severity value of 8.2.
The affected software is NVIDIA DGX A100 Firmware.
The potential impacts of CVE-2022-42276 include code execution, escalation of privileges, denial of service, and information disclosure.
No, NVIDIA DGX A100 is not vulnerable to CVE-2022-42276.
To fix CVE-2022-42276, it is recommended to apply the latest firmware update provided by NVIDIA.