CVE-2022-31602
MEDIUMNVIDIA DGX A100 Firmware < 22.5.5 - Out-of-bounds Write in IpSecDxe
Title source: llmDescription
NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information disclosure.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://nvidia.custhelp.com/app/answers/detail/a_id/5367
Scores
CVSS v3
6.4
EPSS
0.0005
EPSS Percentile
14.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (1)
nvidia/dgx_a100_firmware
< 22.5.5
Published
Jul 04, 2022
Tracked Since
Feb 18, 2026