CVE-2023-0201

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/04/2023
Last modified:
29/04/2023

Description

NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:* 1.08.00 (excluding)
cpe:2.3:h:nvidia:dgx-2:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools