CVE-2022-42277
Summary
| CVE | CVE-2022-42277 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-13 02:15:00 UTC |
| Updated | 2023-01-20 15:29:00 UTC |
| Description | NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nvidia | Dgx Station A100 | - | All | All | All |
| Operating System | Nvidia | Dgx Station A100 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NVIDIA DGX A100 Server and DGX Station A100 - December 2022 | NVIDIA | MISC | nvidia.custhelp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.