CVE-2023-0204 MEDIUM

CVE-2023-0204

Vendor Nvidia
Product NVIDIA ConnectX Firmware
Weakness CWE-703
Published April 22, 2023
Last update February 4, 2025

CVSS base score

6.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.

Key dates

02Disclosure timeline

April 22, 2023 CVE published
February 4, 2025 Record updated