NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and information disclosure.
References
Link | Resource |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5367 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: nvidia
Published: 2022-07-04T18:10:36
Updated: 2022-07-04T18:10:36
Reserved: 2022-05-24T00:00:00
Link: CVE-2022-31603
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-04T18:15:08.207
Modified: 2022-07-13T13:20:05.753
Link: CVE-2022-31603
JSON object: View
Redhat Information
No data.
CWE