7.8

CVE-2023-25522







NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuration information in an unexpected format.  A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.







Data is provided by the National Vulnerability Database (NVD)
NvidiaDgx A100 Firmware SwEditionsbios Version < 1.21
   NvidiaDgx A100 Version-
NvidiaDgx A800 Firmware SwEditionsbios Version < 1.21
   NvidiaDgx A800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.064
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@nvidia.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.