CVE-2022-42277: High severity nvidia dgx station a100 firmware vulnerability
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA DGX Station vulnerability?
The vulnerability ID for this NVIDIA DGX Station vulnerability is CVE-2022-42277.
What is the affected software for this vulnerability?
The affected software for this vulnerability is NVIDIA DGX Station A100 Firmware.
What is the severity rating of CVE-2022-42277?
The severity rating of CVE-2022-42277 is high with a severity value of 8.2.
How can a local user exploit this vulnerability?
A local user with elevated privileges can exploit this vulnerability by reading, writing, and erasing flash, leading to code execution, escalation of privileges, denial of service, and information disclosure.
Is NVIDIA DGX Station A100 vulnerable to this vulnerability?
No, NVIDIA DGX Station A100 is not vulnerable to this vulnerability.