← Back

CVE-2023-25507

nvd nist
Published: Apr 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, and data tampering.

Affected (1)

Products: Nvidia: Bmc
1 product
Bmc
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.39.30
Running on/withPlatform Versions
Nvidia
Dgx 1
All versions

References (2)

Source: psirt@nvidia.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.