Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42276


NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.


Published

2023-01-13T02:15:07.847

Last Modified

2024-11-21T07:24:38.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-288
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System nvidia dgx_a100_firmware < 1.18 Yes
Hardware nvidia dgx_a100 - No

References