NVIDIA DGX-2

CPE Details

NVIDIA DGX-2
-
2020-12-29 13:51 +00:00
2020-12-29 13:51 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:h:nvidia:dgx-2:-:*:*:*:*:*:*:*

Informations

Vendor

nvidia

Product

dgx-2

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-0207 2023-04-22 02:28 +00:00 NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
7.5
HIGH
CVE-2023-0201 2023-04-22 02:22 +00:00 NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.
6.7
MEDIUM
CVE-2023-0200 2023-04-22 02:21 +00:00 NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.
7.5
HIGH
CVE-2021-34400 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.
4.4
MEDIUM
CVE-2021-34399 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.
4.4
MEDIUM
CVE-2021-23219 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.
4.1
MEDIUM
CVE-2021-1125 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.
4.4
MEDIUM
CVE-2021-1105 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.
4.4
MEDIUM
CVE-2021-1088 2021-11-20 13:55 +00:00 NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.
4.4
MEDIUM
CVE-2020-11488 2020-10-29 02:35 +00:00 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.
6.7
MEDIUM
CVE-2020-11489 2020-10-29 02:35 +00:00 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.
7.5
HIGH
CVE-2020-11487 2020-10-29 02:35 +00:00 NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.
7.5
HIGH
CVE-2020-11483 2020-10-29 02:35 +00:00 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-coded credentials, which may lead to elevation of privileges or information disclosure.
9.8
CRITICAL
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.