CVE-2022-42289: OS Command Injection
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA BMC vulnerability?
The vulnerability ID for this NVIDIA BMC vulnerability is CVE-2022-42289.
What is the title of this NVIDIA BMC vulnerability?
The title of this NVIDIA BMC vulnerability is "NVIDIA BMC contains a vulnerability in SPX REST API where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering."
What is the severity of CVE-2022-42289?
The severity of CVE-2022-42289 is high with a CVSS score of 8.8.
What software is affected by this vulnerability?
The NVIDIA DGX A100 Firmware version up to and excluding 00.19.07 is affected by this vulnerability.
How can an attacker exploit this vulnerability?
An authorized attacker can exploit this NVIDIA BMC vulnerability by injecting arbitrary shell commands through the SPX REST API, potentially leading to code execution, denial of service, information disclosure, and data tampering.