CVE-2023-25528: Critical severity nvidia dgx h100 firmware vulnerability
NVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25528?
CVE-2023-25528 is a vulnerability in the NVIDIA DGX H100 baseboard management controller (BMC) that allows an unauthenticated attacker to cause a stack overflow by sending a specially crafted network packet, potentially leading to arbitrary code execution or denial of service.
What is the severity of CVE-2023-25528?
The severity of CVE-2023-25528 is critical, with a severity value of 9.8.
What software is affected by CVE-2023-25528?
The affected software is the NVIDIA DGX H100 baseboard management controller (BMC) firmware version 23.08.18.
How can an attacker exploit CVE-2023-25528?
An attacker can exploit CVE-2023-25528 by sending a specially crafted network packet to the vulnerable web server plugin in the NVIDIA DGX H100 BMC, causing a stack overflow and potentially executing arbitrary code or causing denial of service.
Is the NVIDIA DGX H100 itself vulnerable to CVE-2023-25528?
No, the NVIDIA DGX H100 itself is not vulnerable to CVE-2023-25528.