CVE-2023-25508
CVE-2023-25508
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
22 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure, and data tampering.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
NVIDIA · NVIDIA DGX serversWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →