Database/Firmware, BMC & network fabric
NVIDIA DGX BMC (IPMI handler): Buffer overflow in the IPMI handler of the NVIDIA DGX BMC
CVSS 7.8CVE-2023-25505Firmware, BMC & network fabriccurated
Impact
Buffer overflow in the IPMI handler of the NVIDIA DGX BMC — code execution on the BMC of a GPU node
Who can reach it
Local / IPMI
What to do
DGX BMC firmware update through NVIDIA's own bundle; DGX firmware bundles are monolithic, so this pulls in unrelated component updates and a longer maintenance window
References
Related entries
- AMD Secure Processor - XGMI Trusted Agent (TOCTOU): A TOCTOU race in the ASP's XGMI Trusted Agent lets an attackerCVE-2023-31324 · AMD Secure Processor - XGMI Trusted Agent (TOCTOU)High
- Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method): The firmware reads a runtime UEFI variableCVE-2023-34195 · Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method)High
- AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turnCVE-2023-34332 · AMI MegaRAC SPx 12 / SPx 13 (BMC)High
- AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-networkCVE-2023-34333 · AMI MegaRAC SPx (untrusted pointer dereference)High
- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableCVE-2023-34853 · Supermicro X12DPG-QR BIOS 1.4bHigh
- Dell SmartFabric Storage Software (restricted shell in SSH): OS command injection escaping the restricted shell of theCVE-2023-43068 · Dell SmartFabric Storage Software (restricted shell in SSH)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.