"value":"NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"cweId":"CWE-78"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"NVIDIA",
"product":{
"product_data":[
{
"product_name":"NVIDIA DGX servers",
"version":{
"version_data":[
{
"version_value":"All BMC firmware versions prior to 00.19.07",