NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.
An attacker sends a specially crafted network packet to the KVM daemon running on the BMC (Baseboard Management Controller) of an NVIDIA DGX A100 device. This packet causes a stack-based buffer overflow (CWE-121, CWE-787), which allows overwriting critical memory structures. The attack requires no authentication or user interaction, and its effects extend beyond the isolated component (scope changed).
An attacker can gain the ability to execute arbitrary code (RCE) on a vulnerable device, as well as cause denial of service (DoS), disclosure of sensitive information, and data manipulation.
Apply patches available from the manufacturer according to references published by NVIDIA at: https://nvidia.custhelp.com/app/answers/detail/a_id/5510
NVIDIA DGX A100 and BMC firmware of NVIDIA DGX A100 devices — specific versions indicated in the manufacturer's references (https://nvidia.custhelp.com/app/answers/detail/a_id/5510)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HNvidia Dgx A100
HWNvidiaall versionsNvidia Dgx A100 Firmware
OSNvidia< 00.22.05
Related vulnerabilities
NVIDIA DGX A100 BMC: stack corruption w daemonie KVM umożliwiający RCE
Stack overflow w BMC KVM daemon NVIDIA DGX A100 — RCE bez uwierzytelnienia
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that c...
NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local a...
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input valid...