CVE-2023-31035: CVE
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31035?
CVE-2023-31035 has a high severity rating due to the potential for arbitrary code execution at the SMM level.
How do I fix CVE-2023-31035?
To mitigate CVE-2023-31035, update your NVIDIA DGX A100 firmware to the latest version beyond 1.25.
What are the potential impacts of exploiting CVE-2023-31035?
Exploiting CVE-2023-31035 may lead to code execution, denial of service, and escalation of privileges.
Which devices are affected by CVE-2023-31035?
CVE-2023-31035 affects the NVIDIA DGX A100 firmware versions up to 1.25.
Who can exploit CVE-2023-31035?
An unauthorized user with local access may exploit CVE-2023-31035 due to the SMI callout vulnerability.