CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-13 04:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-42287

Mitre link : CVE-2022-42287

CVE.ORG link : CVE-2022-42287


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')