NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45351 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5435 |
|
History
Mon, 07 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2025-04-07T15:29:51.185Z
Reserved: 2022-10-03T14:20:26.205Z
Link: CVE-2022-42276
Updated: 2024-08-03T13:03:45.885Z
Status : Modified
Published: 2023-01-13T02:15:07.847
Modified: 2024-11-21T07:24:38.563
Link: CVE-2022-42276
No data.
OpenCVE Enrichment
No data.
EUVD