CRITICAL🇵🇱 Wersja polska

CVE-2023-31030

CVSS 9.3v3.1pub. 2024-01-12upd. 2024-11-21

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network packet to the KVM daemon running on the BMC (Baseboard Management Controller) of an NVIDIA DGX A100 device. This packet causes a stack-based buffer overflow (CWE-121, CWE-787), which allows overwriting critical memory structures. The attack requires no authentication or user interaction, and its effects extend beyond the isolated component (scope changed).

Impact

An attacker can gain the ability to execute arbitrary code (RCE) on a vulnerable device, as well as cause denial of service (DoS), disclosure of sensitive information, and data manipulation.

Mitigation & patch

Apply patches available from the manufacturer according to references published by NVIDIA at: https://nvidia.custhelp.com/app/answers/detail/a_id/5510

Who is affected

NVIDIA DGX A100 and BMC firmware of NVIDIA DGX A100 devices — specific versions indicated in the manufacturer's references (https://nvidia.custhelp.com/app/answers/detail/a_id/5510)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Nvidia Dgx A100

    HW
    Nvidia
    all versions
  • Nvidia Dgx A100 Firmware

    OS
    Nvidia
    < 00.22.05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth BypassDoS
CWE
References

Related vulnerabilities

CVE-2023-31024CRITICAL9.0PL ✓same product

NVIDIA DGX A100 BMC: stack corruption w daemonie KVM umożliwiający RCE

CVE-2023-31029CRITICAL9.3PL ✓same product

Stack overflow w BMC KVM daemon NVIDIA DGX A100 — RCE bez uwierzytelnienia

CVE-2023-31035HIGH7.5same product

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that c...

CVE-2023-31032HIGH7.5same product

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local a...

CVE-2023-25522HIGH7.5same product

NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input valid...