PT-2022-3333 · Nvidia · Nvidia Dgx A100

Published

2022-07-01

·

Updated

2022-07-12

·

CVE-2022-28200

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA DGX A100 (affected versions not specified)
Description The issue is related to a buffer overflow in the SBIOS component of the BiosCfgTool in NVIDIA DGX A100 servers. This can allow an attacker to execute arbitrary code, escalate privileges, cause a denial of service, or disclose information. A local user with elevated privileges can read and write beyond intended bounds in SMRAM, potentially impacting other components.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04081
CVE-2022-28200

Affected Products

Nvidia Dgx A100