CVE-2023-31037

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
24/01/2024
Last modified:
31/01/2024

Description

<br /> NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:bluefield_bmc:2.8.2-46:*:*:*:lts:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.04:*:*:*:-:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.07:*:*:*:-:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.09:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:bluefield_2_ga:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:bluefield_2_lts:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:bluefield_3_ga:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools