NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-coded credentials, which may lead to elevation of privileges or information disclosure.
2020-10-29T04:15:10.593
2024-11-21T04:57:59.383
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | intel | bmc_firmware | < 3.38.30 | Yes |
| Hardware | nvidia | dgx-1 | - | No |
| Operating System | intel | bmc_firmware | < 1.06.06 | Yes |
| Hardware | nvidia | dgx-2 | - | No |