CVE-2022-42279: OS Command Injection
Published Jan 13, 2023
·Updated
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
Affected Software
2 affected components
Nvidia Dgx A100 Firmware<00.19.07
Nvidia DGX A100
Event History
Jan 13, 2023
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA BMC vulnerability?
The vulnerability ID is CVE-2022-42279.
2
What is the severity of CVE-2022-42279?
The severity of CVE-2022-42279 is high with a severity value of 8.8.
3
Which software is affected by CVE-2022-42279?
The NVIDIA DGX A100 Firmware versions up to and excluding 00.19.07 are affected by CVE-2022-42279.
4
What can an authorized attacker do with CVE-2022-42279?
An authorized attacker can inject arbitrary shell commands, potentially leading to code execution, denial of service, information disclosure, and data tampering.
5
How can I fix CVE-2022-42279?
It is recommended to update to a fixed version of the NVIDIA DGX A100 Firmware to mitigate CVE-2022-42279.