CVE-2023-0200

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/04/2023
Last modified:
29/04/2023

Description

NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:* 1.08.00 (excluding)
cpe:2.3:h:nvidia:dgx-2:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools