CVE-2022-42275

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 7.7
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory
Summary
  • (es) El controlador NVIDIA BMC IPMI permite que un host no autenticado escriba en una memoria flash SPI del host sin pasar por las protecciones de arranque seguro. Esto puede provocar una pérdida de integridad y denegación de servicio.

Information

Published : 2023-01-13 01:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42275

Mitre link : CVE-2022-42275

CVE.ORG link : CVE-2022-42275


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function