NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5692 |
![]() ![]() |
History
Wed, 17 Sep 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
Weaknesses | CWE-1244 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2025-09-17T22:27:15.541Z
Reserved: 2025-01-14T01:07:19.940Z
Link: CVE-2025-23337

No data.

Status : Received
Published: 2025-09-17T23:15:36.500
Modified: 2025-09-17T23:15:36.500
Link: CVE-2025-23337

No data.

No data.