CVE-2023-31034

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:dgx_a100_firmware:*:*:*:*:sbios:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

19 Jan 2024, 13:27

Type Values Removed Values Added
CPE cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:dgx_a100_firmware:*:*:*:*:sbios:*:*:*
Summary
  • (es) NVIDIA DGX A100 SBIOS contiene una vulnerabilidad en la que un atacante local puede provocar que se omitan las comprobaciones de validación de entrada provocando un desbordamiento de enteros. Una explotación exitosa de esta vulnerabilidad puede provocar denegación de servicio, divulgación de información y manipulación de datos.
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.8
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5510 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5510 - Vendor Advisory
First Time Nvidia dgx A100
Nvidia
Nvidia dgx A100 Firmware

12 Jan 2024, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-12 19:15

Updated : 2024-01-19 13:27


NVD link : CVE-2023-31034

Mitre link : CVE-2023-31034

CVE.ORG link : CVE-2023-31034


JSON object : View

Products Affected

nvidia

  • dgx_a100
  • dgx_a100_firmware
CWE
CWE-190

Integer Overflow or Wraparound