Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11488


NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.


Published

2020-10-29T04:15:11.623

Last Modified

2024-11-21T04:57:59.917

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel bmc_firmware < 3.38.30 Yes
Hardware nvidia dgx-1 - No
Operating System intel bmc_firmware < 1.06.06 Yes
Hardware nvidia dgx-2 - No

References