CVE-2023-25529: High severity nvidia dgx h100 firmware vulnerability
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.
Other sources
NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another user’s session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA DGX H100 BMC vulnerability?
The vulnerability ID for this NVIDIA DGX H100 BMC vulnerability is CVE-2023-25529.
What is the severity level of CVE-2023-25529?
The severity level of CVE-2023-25529 is high.
How does this vulnerability in the host KVM daemon impact NVIDIA DGX H100 BMC?
This vulnerability in the host KVM daemon may lead to information disclosure and escalation of privileges on NVIDIA DGX H100 BMC.
What software version of NVIDIA DGX H100 BMC is affected by CVE-2023-25529?
The NVIDIA DGX H100 BMC firmware version up to exclusive 23.08.18 is affected by CVE-2023-25529.
How can I fix the vulnerability in NVIDIA DGX H100 BMC?
To fix the vulnerability in NVIDIA DGX H100 BMC, it is recommended to update the firmware to a version beyond 23.08.18.