CVE-2022-42278: Buffer Overflow
Published Jan 13, 2023
·Updated
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
Affected Software
2 affected components
Nvidia BMC<00.19.07
Nvidia DGX A100
Event History
Jan 13, 2023
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA BMC vulnerability?
The vulnerability ID for this NVIDIA BMC vulnerability is CVE-2022-42278.
2
What is the severity of CVE-2022-42278?
CVE-2022-42278 has a severity rating of 7.8 (High).
3
What is the affected software for CVE-2022-42278?
The affected software for CVE-2022-42278 is NVIDIA BMC version up to exclusive 00.19.07.
4
What are the potential consequences of CVE-2022-42278?
CVE-2022-42278 may lead to code execution, denial of service, information disclosure, and data tampering.
5
Where can I find more information about CVE-2022-42278?
More information about CVE-2022-42278 can be found at https://nvidia.custhelp.com/app/answers/detail/a_id/5435