First published: Fri Jan 12 2024(Updated: )
NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NVIDIA DGX A100 firmware | <1.25 | |
NVIDIA DGX A100 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31031 is considered to be a high-severity vulnerability due to its potential to allow code execution and data tampering.
To mitigate CVE-2023-31031, users should upgrade the NVIDIA DGX A100 firmware to the latest version beyond 1.25.
CVE-2023-31031 is a heap-based buffer overflow vulnerability.
CVE-2023-31031 affects users of the NVIDIA DGX A100 firmware version 1.25 and earlier.
Exploiting CVE-2023-31031 may lead to code execution, denial of service, information disclosure, and data tampering.