2023-09-20 02:00:29 +00:00
{
"id" : "CVE-2023-25533" ,
"sourceIdentifier" : "psirt@nvidia.com" ,
"published" : "2023-09-20T01:15:54.900" ,
2023-09-22 18:00:27 +00:00
"lastModified" : "2023-09-22T17:47:22.070" ,
"vulnStatus" : "Analyzed" ,
2023-09-20 02:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to information disclosure, code execution, and escalation of privileges."
2023-09-20 12:00:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "NVIDIA DGX H100 BMC contiene una vulnerabilidad en la interfaz de usuario web, donde un atacante puede provocar una validaci\u00f3n de entrada incorrecta. Una explotaci\u00f3n exitosa de esta vulnerabilidad puede conducir a la divulgaci\u00f3n de informaci\u00f3n, la ejecuci\u00f3n de c\u00f3digo y la escalada de privilegios."
2023-09-20 02:00:29 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-22 18:00:27 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
2023-09-20 02:00:29 +00:00
{
"source" : "psirt@nvidia.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 8.3 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.7 ,
"impactScore" : 6.0
}
]
} ,
"weaknesses" : [
2023-09-22 18:00:27 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2023-09-20 02:00:29 +00:00
{
"source" : "psirt@nvidia.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-20"
}
]
}
] ,
2023-09-22 18:00:27 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:nvidia:dgx_h100_firmware:*:*:*:*:bmc:*:*:*" ,
"versionEndExcluding" : "23.08.18" ,
"matchCriteriaId" : "E5A50133-6664-4379-A1E4-A1626B9CBDB1"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:nvidia:dgx_h100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3B945E1-9A87-41B7-9535-939BE61DA499"
}
]
}
]
}
] ,
2023-09-20 02:00:29 +00:00
"references" : [
{
"url" : "https://nvidia.custhelp.com/app/answers/detail/a_id/5473" ,
2023-09-22 18:00:27 +00:00
"source" : "psirt@nvidia.com" ,
"tags" : [
"Vendor Advisory"
]
2023-09-20 02:00:29 +00:00
}
]
}