CVE-2023-25506

NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:sbios:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*

History

29 Apr 2023, 03:05

Type Values Removed Values Added
CPE cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:sbios:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
References (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5458 - (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5458 - Vendor Advisory
CWE CWE-787

22 Apr 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-22 03:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-25506

Mitre link : CVE-2023-25506

CVE.ORG link : CVE-2023-25506


JSON object : View

Products Affected

nvidia

  • sbios
  • dgx-1
CWE
CWE-787

Out-of-bounds Write

CWE-788

Access of Memory Location After End of Buffer