CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

24 Jan 2023, 16:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-434
CPE cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
References (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory
First Time Nvidia dgx A100
Nvidia
Nvidia bmc

13 Jan 2023, 05:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-13 04:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-42287

Mitre link : CVE-2022-42287

CVE.ORG link : CVE-2022-42287


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')