CVE-2022-42280

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/01/2023
Last modified:
24/01/2023

Description

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:* 00.19.07 (excluding)
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools