CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:24

Type Values Removed Values Added
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory () https://nvidia.custhelp.com/app/answers/detail/a_id/5435 - Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 6.0
Summary
  • (es) NVIDIA BMC contiene una vulnerabilidad en el controlador IPMI, donde un atacante autorizado puede cargar y descargar archivos arbitrarios bajo ciertas circunstancias, lo que puede provocar denegación de servicio, escalada de privilegios, divulgación de información y manipulación de datos.

Information

Published : 2023-01-13 04:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42287

Mitre link : CVE-2022-42287

CVE.ORG link : CVE-2022-42287


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type