First published: Sat Apr 22 2023(Updated: )
NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Baseboard Management Controller (BMC) | <1.08.00 | |
NVIDIA DGX-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the NVIDIA DGX-2 SBIOS vulnerability is CVE-2023-0201.
The severity of CVE-2023-0201 is medium, with a CVSS score of 6.7.
The NVIDIA DGX-2 SBIOS vulnerability affects the NVIDIA BMC software version up to exclusive 1.08.00.
The potential impacts of CVE-2023-0201 include code execution, denial of service, compromised integrity, and information disclosure.
To learn more about CVE-2023-0201 and its mitigation, you can visit the following reference: https://nvidia.custhelp.com/app/answers/detail/a_id/5449