Описание
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 00.19.07 (исключая)
Одновременно
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00435
Низкий
7.2 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-119
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.8
github
около 3 лет назад
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
EPSS
Процентиль: 62%
0.00435
Низкий
7.2 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-119
NVD-CWE-noinfo