First published: Mon Jul 03 2023(Updated: )
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Dgx A100 Firmware | <1.21 | |
NVIDIA DGX A100 | ||
Nvidia Dgx A800 Firmware | <1.21 | |
Nvidia Dgx A800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25521 is a vulnerability in NVIDIA DGX A100/A800 SBIOS that allows an attacker to execute with unnecessary privileges.
The severity of CVE-2023-25521 is high with a CVSS score of 7.8.
NVIDIA DGX A100 is affected by CVE-2023-25521, allowing attackers to execute with unnecessary privileges.
CVE-2023-25521 can be exploited by leveraging a weakness in input parameter validation.
The affected software versions of CVE-2023-25521 are NVIDIA DGX A100/A800 firmware versions up to 1.21 SBIOS.
No, NVIDIA DGX A800 is not vulnerable to CVE-2023-25521.
To mitigate CVE-2023-25521, it is recommended to update to a version of NVIDIA DGX A100/A800 firmware that is not affected by the vulnerability.
More information about CVE-2023-25521 can be found at the following reference: [link](https://nvidia.custhelp.com/app/answers/detail/a_id/5461).