Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wh7f-qrp8-9qqv

Опубликовано: 22 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3

Дефекты

CWE-787
CWE-788

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3

Дефекты

CWE-787
CWE-788