PT-2020-12729 · Nvidia+1 · Nvidia Dgx+2

Denis Kolegov

+1

·

Published

2020-10-29

·

Updated

2021-07-21

·

CVE-2020-11616

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NVIDIA DGX servers versions prior to 3.38.30
Description The issue is related to a weakness in the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package, which implements the IPMI protocol in the AMI BMC firmware. This weakness may lead to information disclosure because the PRNG algorithm is not cryptographically strong.
Recommendations For versions prior to 3.38.30, update the BMC firmware to version 3.38.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPMI protocol to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11616

Affected Products

Ami Bmc
Jsol
Nvidia Dgx