NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
The vulnerability is located in the KVM daemon running within the BMC of the NVIDIA DGX A100 device. An attacker sends a specially crafted network packet that causes a stack buffer overflow (CWE-121, CWE-787) — data is written outside the intended memory area. No authentication or user interaction is required, and the attack can be conducted locally (AV:L vector according to CVSS). Successful exploitation allows the attacker to take control of the BMC process.
An attacker can lead to arbitrary code execution (RCE), denial of service (DoS), information disclosure, and data manipulation at the BMC controller level. BMC compromise potentially provides deep access to hardware management, independent of the host operating system.
Apply patches available from the manufacturer in accordance with references — detailed information about updated firmware versions is available in the NVIDIA security bulletin at https://nvidia.custhelp.com/app/answers/detail/a_id/5510
NVIDIA DGX A100 and NVIDIA DGX A100 Firmware software — specific versions indicated in manufacturer references (https://nvidia.custhelp.com/app/answers/detail/a_id/5510)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HNvidia Dgx A100
HWNvidiaall versionsNvidia Dgx A100 Firmware
OSNvidia< 00.22.05
Related vulnerabilities
NVIDIA DGX A100 BMC: stack corruption w daemonie KVM umożliwiający RCE
NVIDIA DGX A100 BMC — stack overflow w demonze KVM umożliwia RCE
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that c...
NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local a...
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input valid...