NVIDIA DGX-1 contains a vulnerability in Ofbd in AMI SBIOS, where a preconditioned heap can allow a user with elevated privileges to cause an access beyond the end of a buffer, which may lead to code execution, escalation of privileges, denial of service and information disclosure. The scope of the impact of this vulnerability can extend to other components.
History

Wed, 05 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2025-02-04T19:03:47.410Z

Reserved: 2023-02-07T02:57:11.656Z

Link: CVE-2023-25506

cve-icon Vulnrichment

Updated: 2024-08-02T11:25:18.390Z

cve-icon NVD

Status : Modified

Published: 2023-04-22T03:15:10.107

Modified: 2024-11-21T07:49:37.973

Link: CVE-2023-25506

cve-icon Redhat

No data.