ZeroHour

CVE-2022-31603

CVSS 3.1
6.7 medium
EPSS
<1%p11
Published
()
Modified
Description

NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and information disclosure.

Vendors
nvidia
Products
dgx a100 firmware
Weakness
CWE-129
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.