First published: Wed Sep 20 2023(Updated: )
NVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
Credit: psirt@nvidia.com psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Dgx H100 Firmware | <23.08.18 | |
NVIDIA DGX H100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25528 is a vulnerability in the NVIDIA DGX H100 baseboard management controller (BMC) that allows an unauthenticated attacker to cause a stack overflow by sending a specially crafted network packet, potentially leading to arbitrary code execution or denial of service.
The severity of CVE-2023-25528 is critical, with a severity value of 9.8.
The affected software is the NVIDIA DGX H100 baseboard management controller (BMC) firmware version 23.08.18.
An attacker can exploit CVE-2023-25528 by sending a specially crafted network packet to the vulnerable web server plugin in the NVIDIA DGX H100 BMC, causing a stack overflow and potentially executing arbitrary code or causing denial of service.
No, the NVIDIA DGX H100 itself is not vulnerable to CVE-2023-25528.