CVE-2022-42278

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:24

Type Values Removed Values Added
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory
Summary
  • (es) NVIDIA BMC contiene una vulnerabilidad en SPX REST API, donde un atacante autorizado puede leer y escribir en ubicaciones arbitrarias dentro del contexto de memoria del proceso del servidor IPMI, lo que puede provocar la ejecución de código, denegación de servicio, divulgación de información y manipulación de datos.
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.2

Information

Published : 2023-01-13 02:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42278

Mitre link : CVE-2022-42278

CVE.ORG link : CVE-2022-42278


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

NVD-CWE-noinfo