CVE-2022-42282: Path Traversal
Published Jan 13, 2023
·Updated
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.
Affected Software
2 affected components
Nvidia BMC<00.19.07
Nvidia DGX A100
Event History
Jan 13, 2023
CVE Published
via MITRE·01:38 AM
Data Sourced
via MITRE·01:38 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this NVIDIA BMC vulnerability?
The vulnerability ID of this NVIDIA BMC vulnerability is CVE-2022-42282.
2
What is the title of this NVIDIA BMC vulnerability?
The title of this NVIDIA BMC vulnerability is 'NVIDIA BMC contains a vulnerability in SPX REST API where an authorized attacker can access arbitrary files, which may lead to information disclosure.'
3
What is the severity of CVE-2022-42282?
The severity of CVE-2022-42282 is medium (5.5).
4
What is the affected software for CVE-2022-42282?
The affected software for CVE-2022-42282 is NVIDIA BMC up to version 00.19.07.
5
How can an authorized attacker exploit CVE-2022-42282?
An authorized attacker can exploit CVE-2022-42282 by accessing arbitrary files through the SPX REST API, potentially leading to information disclosure.