Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11486

Опубликовано: 29 окт. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:intel:bmc_firmware:*:*:*:*:*:*:*:*
Версия до 3.38.30 (исключая)
cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02126
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.

EPSS

Процентиль: 84%
0.02126
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434