CVE-2020-11486

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
29/10/2020
Last modified:
05/11/2020

Description

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:bmc_firmware:*:*:*:*:*:*:*:* 3.38.30 (excluding)
cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools