CRITICAL🇵🇱 Wersja polska

CVE-2023-31029

CVSS 9.3v3.1pub. 2024-01-12upd. 2024-11-21

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

🤖 AI Analysis
How it works

The vulnerability is located in the KVM daemon running within the BMC of the NVIDIA DGX A100 device. An attacker sends a specially crafted network packet that causes a stack buffer overflow (CWE-121, CWE-787) — data is written outside the intended memory area. No authentication or user interaction is required, and the attack can be conducted locally (AV:L vector according to CVSS). Successful exploitation allows the attacker to take control of the BMC process.

Impact

An attacker can lead to arbitrary code execution (RCE), denial of service (DoS), information disclosure, and data manipulation at the BMC controller level. BMC compromise potentially provides deep access to hardware management, independent of the host operating system.

Mitigation & patch

Apply patches available from the manufacturer in accordance with references — detailed information about updated firmware versions is available in the NVIDIA security bulletin at https://nvidia.custhelp.com/app/answers/detail/a_id/5510

Who is affected

NVIDIA DGX A100 and NVIDIA DGX A100 Firmware software — specific versions indicated in manufacturer references (https://nvidia.custhelp.com/app/answers/detail/a_id/5510)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Nvidia Dgx A100

    HW
    Nvidia
    all versions
  • Nvidia Dgx A100 Firmware

    OS
    Nvidia
    < 00.22.05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth BypassDoS
CWE
References

Related vulnerabilities

CVE-2023-31024CRITICAL9.0PL ✓same product

NVIDIA DGX A100 BMC: stack corruption w daemonie KVM umożliwiający RCE

CVE-2023-31030CRITICAL9.3PL ✓same product

NVIDIA DGX A100 BMC — stack overflow w demonze KVM umożliwia RCE

CVE-2023-31035HIGH7.5same product

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that c...

CVE-2023-31032HIGH7.5same product

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local a...

CVE-2023-25522HIGH7.5same product

NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input valid...