First published: Mon Jul 03 2023(Updated: )
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuration information in an unexpected format. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Dgx A100 Firmware | <1.21 | |
NVIDIA DGX A100 | ||
Nvidia Dgx A800 Firmware | <1.21 | |
Nvidia Dgx A800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-25522.
The severity of CVE-2023-25522 is high, with a CVSS score of 7.8.
The affected software includes NVIDIA DGX A100/A800 with SBIOS firmware versions up to 1.21.
The potential impacts of exploiting CVE-2023-25522 include denial of service, information disclosure, and data tampering.
Yes, NVIDIA DGX A100/A800 with SBIOS firmware versions up to 1.21 is vulnerable to exploit CVE-2023-25522.
To fix the vulnerability CVE-2023-25522, update the SBIOS firmware of NVIDIA DGX A100/A800 to version 1.22 or higher.
You can find more information about CVE-2023-25522 on the NVIDIA website at https://nvidia.custhelp.com/app/answers/detail/a_id/5461.