Description
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35372 | NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure. |
References
| Link | Providers |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5510 |
|
History
No history.
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2024-08-30T19:10:51.835Z
Reserved: 2023-04-22T02:38:33.414Z
Link: CVE-2023-31035
Updated: 2024-08-02T14:45:25.188Z
Status : Modified
Published: 2024-01-12T19:15:11.057
Modified: 2024-11-21T08:01:17.547
Link: CVE-2023-31035
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD