CVE-2023-31037

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:bluefield_bmc:2.8.2-46:*:*:*:lts:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.04:*:*:*:-:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.07:*:*:*:-:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.09:*:*:*:-:*:*:*
OR cpe:2.3:h:nvidia:bluefield_2_ga:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:bluefield_2_lts:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:bluefield_3_ga:-:*:*:*:*:*:*:*

History

31 Jan 2024, 20:11

Type Values Removed Values Added
First Time Nvidia
Nvidia bluefield 2 Ga
Nvidia bluefield 3 Ga
Nvidia bluefield 2 Lts
Nvidia bluefield Bmc
CWE CWE-78
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5511 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5511 - Vendor Advisory
CPE cpe:2.3:h:nvidia:bluefield_2_lts:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:bluefield_3_ga:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.09:*:*:*:-:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:2.8.2-46:*:*:*:lts:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.07:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:bluefield_2_ga:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:bluefield_bmc:23.04:*:*:*:-:*:*:*

24 Jan 2024, 13:49

Type Values Removed Values Added
Summary
  • (es) NVIDIA Bluefield 2 y Bluefield 3 DPU BMC contienen una vulnerabilidad en ipmitool, donde un usuario root puede provocar la inyección de código mediante una llamada de red. Una explotación exitosa de esta vulnerabilidad puede provocar la ejecución de código en el sistema operativo.

24 Jan 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 03:15

Updated : 2024-01-31 20:11


NVD link : CVE-2023-31037

Mitre link : CVE-2023-31037

CVE.ORG link : CVE-2023-31037


JSON object : View

Products Affected

nvidia

  • bluefield_2_lts
  • bluefield_bmc
  • bluefield_3_ga
  • bluefield_2_ga
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')