First published: Fri Jan 12 2024(Updated: )
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NVIDIA DGX Station A100 firmware | <00.22.05 | |
NVIDIA DGX A100 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31030 is classified as a critical severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2023-31030, update the NVIDIA DGX A100 firmware to a version above 00.22.05.
CVE-2023-31030 affects all NVIDIA DGX A100 systems running firmware version 00.22.05 or earlier.
Yes, CVE-2023-31030 can be exploited remotely by sending specially crafted network packets.
Exploiting CVE-2023-31030 may lead to arbitrary code execution, denial of service, and exposure of sensitive information.