CVE-2023-31024: CVE
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31024?
CVE-2023-31024 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2023-31024?
To remediate CVE-2023-31024, update the NVIDIA DGX A100 firmware to a version greater than 00.22.05.
Who is affected by CVE-2023-31024?
Organizations using the NVIDIA DGX A100 firmware version 00.22.05 or lower are affected by CVE-2023-31024.
What can an attacker achieve by exploiting CVE-2023-31024?
An attacker exploiting CVE-2023-31024 can achieve arbitrary code execution and cause denial of service.
Is authentication required to exploit CVE-2023-31024?
No, exploitation of CVE-2023-31024 can occur without authentication, making it particularly concerning.