Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25506

Опубликовано: 22 апр. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 8.2
EPSS Низкий

Описание

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:nvidia:sbios:*:*:*:*:*:*:*:*
Версия до 52w_3a13 (исключая)
cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3

8.2 High

CVSS3

Дефекты

CWE-788
CWE-787

Связанные уязвимости

CVSS3: 7.5
github
почти 3 года назад

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.

EPSS

Процентиль: 14%
0.00045
Низкий

7.5 High

CVSS3

8.2 High

CVSS3

Дефекты

CWE-788
CWE-787