Vulnerability Description
NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and information disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Dgx A100 Firmware | < 22.5.5 |
| Nvidia | Dgx A100 | - |
Related Weaknesses (CWE)
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5367Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5367Vendor Advisory
FAQ
What is CVE-2022-31603?
CVE-2022-31603 is a vulnerability with a CVSS score of 6.4 (MEDIUM). NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause ...
How severe is CVE-2022-31603?
CVE-2022-31603 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31603?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Dgx A100 Firmware, Nvidia Dgx A100.