First published: Fri Jan 12 2024(Updated: )
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NVIDIA DGX A100 firmware | <1.25 | |
NVIDIA DGX A100 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31035 has a high severity rating due to the potential for arbitrary code execution at the SMM level.
To mitigate CVE-2023-31035, update your NVIDIA DGX A100 firmware to the latest version beyond 1.25.
Exploiting CVE-2023-31035 may lead to code execution, denial of service, and escalation of privileges.
CVE-2023-31035 affects the NVIDIA DGX A100 firmware versions up to 1.25.
An unauthorized user with local access may exploit CVE-2023-31035 due to the SMI callout vulnerability.