NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information disclosure.
2022-07-04T18:15:08.137
2024-11-21T07:04:49.693
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nvidia | dgx_a100_firmware | < 22.5.5 | Yes |
Hardware | nvidia | dgx_a100 | - | No |