CVE-2023-0209

HIGH

NVIDIA DGX-1 SBIOS < 52w_3a13 - Unauthenticated Arbitrary Code Execution via Uncore PEI Module

Title source: llm
STIX 2.1

Description

NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which may lead to arbitrary code execution, denial of service, escalation of privileges assisted by a firmware implant, information disclosure assisted by a firmware implant, data tampering, and SecureBoot bypass.

References (1)

Core 1

Scores

CVSS v3 8.2
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
nvidia/sbios < 52w_3a13
Published Apr 22, 2023
Tracked Since Feb 18, 2026