CVE-2023-31035 HIGH

CVE-2023-31035: CVE

Vendor Nvidia
Product DGX A100
Weakness CWE-20 · Input validation
Published January 12, 2024
Last update August 30, 2024

CVSS base score

7.5/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

Key dates

02Disclosure timeline

January 12, 2024 CVE published
August 30, 2024 Record updated